Ship goa-amount.js inside each landing tree, add an inline fallback when the asset is not yet deployed, keep CHF free of GOA unit names, fix exchange amount_full wiring, and add test-landing-stats.sh (local + live). |
||
|---|---|---|
| .. | ||
| bank-landing | ||
| bonfire | ||
| caddy | ||
| castopod | ||
| exchange-landing | ||
| firewalld | ||
| forgejo | ||
| merchant-landing | ||
| nym | ||
| paivana | ||
| prime | ||
| shared | ||
| systemd | ||
| taler-exchange | ||
| taler-exchange-ansible | ||
| taler-hacktivism | ||
| taler-hacktivism-bank | ||
| tops | ||
| tor | ||
| ports.md | ||
| README.md | ||
Config mirrors (from host koopa)
Directories are named to match live podman container names where possible.
| Directory | Live container | Image (typical) |
|---|---|---|
taler-hacktivism/ |
taler-hacktivism |
taler-hacktivism-live:landing |
taler-hacktivism-bank/ |
taler-hacktivism-bank |
taler-hacktivism-banking:live |
taler-exchange/ |
conf inside exchange container | (see exchange-ansible) |
taler-exchange-ansible/ |
taler-hacktivism-exchange-ansible |
taler-hacktivism-exchange-ansible:landing |
bank-landing/ exchange-landing/ merchant-landing/ |
nginx landing snippets | ports 9013–9015 |
koopa-* apps |
koopa-castopod, koopa-bonfire, … |
compose mirrors |
tops/ |
koopa-tops-ng1 … ng3 |
nginxinc/nginx-unprivileged:1.27-alpine (non-root, :8080) |
caddy/ firewalld/ systemd/ |
host services | |
tor/ |
koopa-tor-relay (podman host net) |
localhost/koopa-tor-relay:latest (non-root uid 1000) |
nym/ |
koopa-nym (nym.com nym-node) |
localhost/koopa-nym:latest (non-root uid 1000) |
paivana/ |
koopa-paivana (+ upstream) |
localhost/koopa-paivana:latest (non-root); upstream unprivileged nginx |
forgejo/ |
koopa-forgejo |
rootless image + user: 1000 + userns keep-id |
prime/ |
jellyfin / qbittorrent | linuxserver PUID/PGID=1000 |
Container process privilege policy: service processes must not run as root inside the container when we control the image/compose. Pattern: uid/gid 1000 + rootless podman userns_mode: keep-id (see forgejo/nym/tor/paivana). Official DB images already drop to postgres/redis/mysql. Exceptions: taler-exchange-ansible (lab image with root SSH — not production service), third-party app images without a rootless variant (bonfire/castopod — track upstream).
Authoritative running inventory: host/overview/LIVE.md.
Secrets never live here — SECRETS.md / koopa-admin-secrets.