koopa-admin-log/configs
Hernâni Marques 746d7a41af
scripts/taler-landing: hernani user systemd timer for central stats
Install path for hernani@koopa: oneshot service plus 2-minute timer that
runs the bank full scan and refreshes exchange/merchant stats via podman.
2026-07-17 07:55:00 +02:00
..
bank-landing bank: strip :443 from taler://withdraw URIs for wallet apps. 2026-07-17 01:07:22 +02:00
bonfire docs: new root as prior history lost (orphan + GC); ~215 commits not recoverable 2026-07-13 10:12:00 +02:00
caddy docs: Caddy and ports for paivana.hacktivism.ch 2026-07-13 11:26:09 +02:00
castopod docs: new root as prior history lost (orphan + GC); ~215 commits not recoverable 2026-07-13 10:12:00 +02:00
exchange-landing docs: new root as prior history lost (orphan + GC); ~215 commits not recoverable 2026-07-13 10:12:00 +02:00
firewalld docs: map koopa-nym secrets to koopa-admin-secrets paths 2026-07-16 16:29:19 +02:00
forgejo docs: new root as prior history lost (orphan + GC); ~215 commits not recoverable 2026-07-13 10:12:00 +02:00
merchant-landing docs: new root as prior history lost (orphan + GC); ~215 commits not recoverable 2026-07-13 10:12:00 +02:00
nym nym: polish Containerfile, compose, entrypoint, and README. 2026-07-16 23:50:57 +02:00
paivana paivana: refresh compose, Containerfile, and conf template. 2026-07-16 23:55:31 +02:00
prime docs: new root as prior history lost (orphan + GC); ~215 commits not recoverable 2026-07-13 10:12:00 +02:00
shared docs: new root as prior history lost (orphan + GC); ~215 commits not recoverable 2026-07-13 10:12:00 +02:00
systemd scripts/taler-landing: hernani user systemd timer for central stats 2026-07-17 07:55:00 +02:00
taler-exchange docs: new root as prior history lost (orphan + GC); ~215 commits not recoverable 2026-07-13 10:12:00 +02:00
taler-exchange-ansible docs: new root as prior history lost (orphan + GC); ~215 commits not recoverable 2026-07-13 10:12:00 +02:00
taler-hacktivism docs: new root as prior history lost (orphan + GC); ~215 commits not recoverable 2026-07-13 10:12:00 +02:00
taler-hacktivism-bank bank: raise DEFAULT_DEBT_LIMIT to libeufin amount ceiling. 2026-07-16 20:49:21 +02:00
tops docs: tops compose refresh and configs inventory index. 2026-07-17 01:07:00 +02:00
tor tor: container create helper and relay docs. 2026-07-17 00:30:13 +02:00
ports.md ports: document koopa-nym mixnet verloc and 9080 API 2026-07-16 16:01:40 +02:00
README.md docs: tops compose refresh and configs inventory index. 2026-07-17 01:07:00 +02:00

Config mirrors (from host koopa)

Directories are named to match live podman container names where possible.

Directory Live container Image (typical)
taler-hacktivism/ taler-hacktivism taler-hacktivism-live:landing
taler-hacktivism-bank/ taler-hacktivism-bank taler-hacktivism-banking:live
taler-exchange/ conf inside exchange container (see exchange-ansible)
taler-exchange-ansible/ taler-hacktivism-exchange-ansible taler-hacktivism-exchange-ansible:landing
bank-landing/ exchange-landing/ merchant-landing/ nginx landing snippets ports 90139015
koopa-* apps koopa-castopod, koopa-bonfire, … compose mirrors
tops/ koopa-tops-ng1ng3 nginxinc/nginx-unprivileged:1.27-alpine (non-root, :8080)
caddy/ firewalld/ systemd/ host services
tor/ koopa-tor-relay (podman host net) localhost/koopa-tor-relay:latest (non-root uid 1000)
nym/ koopa-nym (nym.com nym-node) localhost/koopa-nym:latest (non-root uid 1000)
paivana/ koopa-paivana (+ upstream) localhost/koopa-paivana:latest (non-root); upstream unprivileged nginx
forgejo/ koopa-forgejo rootless image + user: 1000 + userns keep-id
prime/ jellyfin / qbittorrent linuxserver PUID/PGID=1000

Container process privilege policy: service processes must not run as root inside the container when we control the image/compose. Pattern: uid/gid 1000 + rootless podman userns_mode: keep-id (see forgejo/nym/tor/paivana). Official DB images already drop to postgres/redis/mysql. Exceptions: taler-exchange-ansible (lab image with root SSH — not production service), third-party app images without a rootless variant (bonfire/castopod — track upstream).

Authoritative running inventory: host/overview/LIVE.md.

Secrets never live here — SECRETS.md / koopa-admin-secrets.