Galene — SFU on CachyOS (koopa)
| Item |
Value |
| Stack |
Galene |
| Image |
localhost/koopa-galene:cachyos (FROM docker.io/cachyos/cachyos) |
| Build |
Go from git tag GALENE_REF (default galene-0.96.3; no release tarballs) |
| Live dir |
/home/hernani/koopa-galene/ |
| Container |
koopa-galene |
| Host port |
9029 = Paivana paywall; Galene HTTP backend 127.0.0.1:19129 (-insecure) |
| Public site |
galene.hacktivism.ch |
Build + up (koopa)
bash /path/to/koopa-admin-log/scripts/galene/build.sh
mkdir -p ~/koopa-galene && cp -a /path/to/koopa-admin-log/configs/galene/compose.yml ~/koopa-galene/
cd ~/koopa-galene && podman-compose up -d
Caddy
sudo bash /path/to/koopa-admin-log/scripts/caddy/caddy-apply.sh \
--snippet /path/to/koopa-admin-log/configs/caddy/galene.hacktivism.ch.caddy \
--site galene.hacktivism.ch --port 9029 --label galene
DNS + VeciGate for the hostname; WebRTC UDP ports documented when first room is live.
Notes
- Volume
./data must not hide UI assets; entrypoint passes -static /opt/galene/static.
- Example group: copy
groups/hacktivism.json.example → ~/koopa-galene/data/groups/hacktivism.json (change op password).
- WebRTC UDP: compose publishes 10000–10099/udp; set the same range in VeciGate DNAT → koopa. Entrypoint uses
-udp-range (GALENE_UDP_RANGE).
- Built-in TURN (
-turn auto) logs no public addresses until the host has a reachable public/mapped address; fix UDP/NAT first, then re-check logs.