koopa-admin-log/host/overview/LIVE.md
2026-07-13 11:26:09 +02:00

107 lines
4.7 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# Live inventory — koopa (2026-07-13)
Snapshot of **what runs on host koopa** (openSUSE Tumbleweed). No secrets.
Refresh command ideas:
```bash
hostname; date -R
podman ps --format 'table {{.Names}}\t{{.Image}}\t{{.Status}}\t{{.Ports}}'
systemctl is-active caddy
systemctl --user is-active container-koopa-tor-relay
ss -lntp | grep -E '90[0-9]{2}|9200|8080'
```
## Host
| Item | Value |
|------|--------|
| Hostname | `koopa` |
| Role | App host behind VeciGate (WAN :80→9000, :443→9001) |
| Edge | Caddy **9000/9001**, systemd socket proxies **80/443** |
| Tor | **podman `koopa-tor-relay`** (host net) ORPort **8080** dual-stack, ControlPort **127.0.0.1:9051** — not host `tor.service` |
## Running podman containers
| Name | Image | Ports (host) | Public site |
|------|--------|--------------|-------------|
| `taler-hacktivism` | `localhost/taler-hacktivism-live:landing` | **9010**, **9015** | `taler.hacktivism.ch` |
| **`taler-hacktivism-exchange-ansible`** | `localhost/taler-hacktivism-exchange-ansible:landing` | **9011**, **9014** | `exchange.hacktivism.ch` |
| `taler-hacktivism-bank` | **`localhost/taler-hacktivism-banking:live`** | **9012**, **9013** | `bank.hacktivism.ch` |
| `koopa-castopod` (+ mariadb, redis) | `castopod/castopod:1` | **9020** | `castopod.hacktivism.ch` |
| `koopa-bonfire` (+ postgres) | `bonfire:1.0.5-social-amd64` | **9021** | `bonfire.hacktivism.ch` |
| `koopa-prime-jellyfin` | `linuxserver/jellyfin:10.10.7` | **9022** | `prime.hacktivism.ch` |
| `koopa-prime-qbittorrent` | `linuxserver/qbittorrent:5.0.4` | **9023**, **6881** | `bt.hacktivism.ch` |
| `koopa-forgejo` (+ postgres) | `forgejo:11-rootless` | **9024**, **9200** | `git.hacktivism.ch` |
| **`koopa-paivana`** (+ upstream) | `localhost/koopa-paivana:latest` | **9025** | `paivana.hacktivism.ch` |
| **`koopa-tor-relay`** | `localhost/koopa-tor-relay:latest` | **8080**, **9051** (host net) | Tor OR (non-exit) |
| `koopa-tops-ng1` | `nginx` | **9090** | `tops.ng1.hacktivism.ch` |
| `koopa-tops-ng2` | `nginx` | **9091** | `tops.ng2.hacktivism.ch` |
| `koopa-tops-ng3` | `nginx` | **9092** | `tops.ng3.hacktivism.ch` |
### Naming note (exchange)
Live exchange container is **`taler-hacktivism-exchange-ansible`** (not `taler-hacktivism-exchange-ansible` / not without `-ansible`).
Managed from **`/home/hernani/ansible-taler-exchange/`** (see `configs/taler-exchange-ansible/`).
## Caddy vhosts → backends
| Host | Backend |
|------|---------|
| `taler.hacktivism.ch` | 9010 (API) + 9015 (`/intro`) |
| `exchange.hacktivism.ch` | 9011 + 9014 (`/intro`) |
| `bank.hacktivism.ch` | 9012 + 9013 (`/intro`, terms, privacy) |
| `castopod.hacktivism.ch` | 9020 |
| `bonfire.hacktivism.ch` | 9021 |
| `prime.hacktivism.ch` | 9022 |
| `bt.hacktivism.ch` | 9023 |
| `git.hacktivism.ch` | 9024 (HTTP); git-SSH **9200** host-direct |
| `paivana.hacktivism.ch` | 9025 (paivana-httpd GOA paywall) |
| `tops.ng1.hacktivism.ch` | 9090 |
| `tops.ng2.hacktivism.ch` | 9091 |
| `tops.ng3.hacktivism.ch` | 9092 |
Config: `/etc/caddy/Caddyfile` (mirror `configs/caddy/Caddyfile`).
## Paths on host (`hernani`)
| Path | Role |
|------|------|
| `~/ansible-taler-exchange/` | Ansible + scripts for exchange-ansible container |
| `~/koopa-castopod/` | Castopod compose |
| `~/koopa-bonfire/` | Bonfire compose + gitbot |
| `~/koopa-prime/` | Jellyfin + qBittorrent |
| `~/koopa-forgejo/` | Forgejo rootless |
| `~/koopa-paivana/` | Paivana paywall (`koopa-paivana`) |
| `~/koopa-tops/` | tops.ng1ng3 (`koopa-tops-ng*`) |
| `~/koopa-caddy/` | Caddyfile working tree on host |
| `~/koopa-tor-relay/` | Tor relay container (torrc, data/identity, log) |
## Start models
| Stack | How |
|-------|-----|
| Taler merchant/bank | root `start_base_services_*` → service user → `/usr/local/bin/start_*.sh` |
| Exchange (GOA) | `~/ansible-taler-exchange/run-container-koopa.sh` then `deploy-hacktivism-goa.sh` |
| User apps | `cd ~/koopa-* && podman-compose up -d` |
| tops (ng1ng3) | user unit `container-koopa-tops.service` (linger) |
## Config mirrors in this repo (`configs/`)
| Live container | Git path |
|----------------|----------|
| `taler-hacktivism` | `configs/taler-hacktivism/` |
| `taler-hacktivism-bank` (image **…-banking**) | `configs/taler-hacktivism-bank/` |
| `taler-hacktivism-exchange-ansible` | `configs/taler-exchange-ansible/` + conf in `configs/taler-exchange/` |
| `koopa-tops-ng1``ng3` | `configs/tops/` |
## Related docs in this repo
| Topic | Doc |
|-------|-----|
| Ports | `configs/ports.md` |
| Diagram | `host/overview/services.md` |
| Exchange Ansible (koopa) | `configs/taler-exchange-ansible/` |
| Forgejo | `2026/2026-07-10--forgejo-rootless.md` |
| Bonfire public feeds | `configs/bonfire/public-feeds.md` |
| Castopod content | `2026/2026-07-09--castopod-content.md` |