koopa-admin-log/configs/nym/README.md
Hernâni Marques e7469b47f9 nym: polish Containerfile, compose, entrypoint, and README.
Host-side binary download notes and compose port mapping clarifications.
2026-07-16 23:50:57 +02:00

3.2 KiB

Nym node — koopa (koopa-nym)

Podman container koopa-nym runs a nym-node from nym.com (Nym mixnet / NymVPN network).
Host layout (live): ~/koopa-nym/.
Mirror in this repo: configs/nym/.

Setting Value
Container koopa-nym
Image localhost/koopa-nym:latest
Process user non-root nym uid/gid 1000 (USER + compose userns_mode: keep-id)
Default mode mixnode (safest on a home host; no open-internet exit)
Optional modes entry-gateway, exit-gateway (+ WireGuard for dVPN) — see env
Local ID koopa-nym
Data ~/.nym/nym-nodes/koopa-nym/ inside volume ./data
Operator T&Cs must pass --accept-operator-terms-and-conditions every run

Ports (host) — avoid Caddy 9000/9001 and Tor 8080

Role nym-node default Host publish
HTTP API / swagger 8080 9080
Mixnet Sphinx 1789 1789
Verloc 1790 1790
Entry client WS 9000 19000 (only if gateway mode)
WireGuard 51822 51822 (only if WG enabled)

VeciGate / firewall: open only what the chosen mode needs.
Exit-gateway and WireGuard expose the host IP to abuse complaints — read Nym exit counsel before enabling.

Files

File Role
Containerfile Debian slim + nym-node binary
entrypoint.sh env → nym-node run …
compose.yml podman/docker compose
.env.example non-secret knobs
container-koopa-nym.service systemd --user unit template

Ops (sketch)

cd ~/koopa-nym   # or this mirror
cp .env.example .env   # edit PUBLIC_IPS, LOCATION, MODE
# host data must be writable by uid 1000 (hernani)
mkdir -p data && chown -R "$(id -u):$(id -g)" data
# sync compose + entrypoint from admin-log if this tree is a copy
podman build -t localhost/koopa-nym:latest -f Containerfile .
# IMPORTANT: port maps only apply on create — not on plain podman start
podman compose down
podman compose up -d --force-recreate --build
podman exec koopa-nym id                # expect uid=1000(nym)
podman port koopa-nym                   # must list 1789/tcp+udp and 1790/tcp
ss -lntp | grep -E '1789|1790|9080'
# bonding: use Nym wallet / harbourmaster; node must accept operator T&Cs
curl -sS http://127.0.0.1:9080/api/v1/roles | jq .

If WAN 1790 is “connection refused” but 1789 works

Almost always container publish/bind, not VeciGate:

  1. Old container created without a solid 1790/tcp map → recreate (above).
  2. Process bound only on [::]:1790 while host proxy expects IPv4 → defaults are now 0.0.0.0:1790.
  3. Confirm: podman port koopa-nym shows 1790/tcp -> 0.0.0.0:1790, then nc -vz WAN 1790.

Secrets layout (values in koopa-admin-secrets):

Live Secrets mirror
~/koopa-nym/.env koopa-admin-secrets/koopa/home-hernani/koopa-nym/.env
~/koopa-nym/data/ host-only (node identity; not git)

Path map: koopa-admin-log/SECRETS.md.

Public listing (explorers): see PUBLIC-LISTING.md.