2026-08-25 16:27:57 +02:00
|
|
|
# De veldvolgorde hieronder is niet vrij: de packaging-documentatie van de
|
|
|
|
|
# officiele appstore schrijft hem voor. Zie de tabel in
|
|
|
|
|
# Docs/Referenties/Umbrel-appstore-spec.md, en de toets in
|
|
|
|
|
# tests/test_server_start_zonder_certificaat.py die hem vasthoudt.
|
|
|
|
|
#
|
|
|
|
|
# Wat de spec niet noemt, staat onderaan dit bestand en niet ertussen. Dan is de
|
|
|
|
|
# voorgeschreven kop letterlijk goed en hoeft er bij inlevering alleen iets weg.
|
|
|
|
|
manifestVersion: 1
|
|
|
|
|
id: whatsnext-electrum-gate
|
|
|
|
|
category: bitcoin
|
|
|
|
|
name: Electrum Gate
|
2026-08-27 15:24:24 +02:00
|
|
|
version: "0.0.16"
|
2026-08-25 16:27:57 +02:00
|
|
|
tagline: Your own node from anywhere, without waiting for Tor
|
|
|
|
|
description: >-
|
|
|
|
|
The privacy win is already yours: you run the Electrum server. A public one gets asked for
|
|
|
|
|
the history of every address in your wallet, and that tells it which addresses and which
|
|
|
|
|
balance belong to one person. Your own server never reports back.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
What is left is a trade. Tor is the more private way in, and every wallet below speaks it.
|
|
|
|
|
But it adds hundreds of milliseconds to every request, it drops when a phone sleeps or
|
|
|
|
|
changes network, and plenty of networks block it outright. Electrum Gate is the other side
|
|
|
|
|
of that trade: a TLS front door on your node. Fast, no fingerprint to type over, and it
|
|
|
|
|
works on any network you happen to be on.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
It reuses the Let's Encrypt certificate your reverse proxy already manages, so there is
|
|
|
|
|
nothing to request and nothing to renew. A renewal is picked up on its own, without
|
|
|
|
|
dropping connections that are already open. You can also upload a certificate you manage
|
|
|
|
|
yourself, if you do not run a reverse proxy on this machine.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Nothing in the middle. The connection runs from your wallet straight to your own node,
|
|
|
|
|
encrypted with a certificate you already own, for a domain you already control. There is no
|
|
|
|
|
account to create, no tunnel service that terminates your traffic along the way, and no
|
|
|
|
|
client to install on every device you use: the wallets below already speak TLS, they only
|
|
|
|
|
need an address. What it does ask of you is one forwarded port on your router.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Useful for wallets connecting from outside your home: Trezor Suite, Electrum, Sparrow,
|
|
|
|
|
BlueWallet, Nunchuk, Blockstream and BitBoxApp. Apps on the Umbrel itself do not need
|
|
|
|
|
it, they already reach the Electrum server directly.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
The dashboard hands you the exact line each of those wallets asks for, and shows block
|
|
|
|
|
height, certificate expiry and whether your Electrum server is answering. Electrs, Fulcrum
|
|
|
|
|
and ElectrumX all work, switchable in the umbrelOS settings.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
What it does not do: hide that the traffic exists. Your domain is public in the certificate
|
|
|
|
|
transparency logs. If that matters more to you than speed, use Tor instead.
|
|
|
|
|
|
|
|
|
|
# Eén verhaal over deze versie, dan één regel per eerdere versie. Niet meer dan
|
|
|
|
|
# dat, en dat staat hier omdat het drie versies achter elkaar fout ging: bij elke
|
|
|
|
|
# release kwam er een nieuwe kop bovenop terwijl de oude tekst eronder bleef
|
|
|
|
|
# staan. In 0.0.9 stond er daardoor drie keer "Earlier releases" en twee keer
|
|
|
|
|
# dezelfde 0.0.4-regel. De toets let er nu op.
|
|
|
|
|
releaseNotes: >-
|
2026-08-27 15:24:24 +02:00
|
|
|
The app now checks its own front door. Until this release it watched whether your Electrum server was
|
|
|
|
|
answering, but never whether the gateway itself was, which is the one thing it exists to do.
|
2026-08-25 16:27:57 +02:00
|
|
|
|
|
|
|
|
|
2026-08-27 15:24:24 +02:00
|
|
|
Every few minutes it opens a connection to its own TLS port, completes the handshake, and compares the
|
|
|
|
|
certificate it gets back with the one you picked. That last part catches something nothing else did: a
|
|
|
|
|
certificate change that nginx never actually applied, which looks fine from the outside and fails at
|
|
|
|
|
your wallet.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
For now the result appears as a line in the activity log when it changes. A tile on the dashboard
|
|
|
|
|
follows in a later release. The check runs every few minutes rather than every minute, and its own
|
|
|
|
|
connections are kept out of the activity log, so the log stays about your wallets.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
What it does not tell you: whether your gateway can be reached from outside. This check runs inside the
|
|
|
|
|
app, so a router that stopped forwarding the port still reads as fine here.
|
2026-08-25 16:27:57 +02:00
|
|
|
|
|
|
|
|
|
|
|
|
|
Earlier releases:
|
|
|
|
|
|
|
|
|
|
|
2026-08-27 15:24:24 +02:00
|
|
|
0.0.15 moved the app store this app comes from to a new address, and pointed every link in this listing
|
|
|
|
|
there. If you added the store at its old address, remove it in umbrelOS and add the new one.
|
|
|
|
|
|
|
|
|
|
|
2026-08-25 16:27:57 +02:00
|
|
|
0.0.14 stopped calling a scan from the internet a refusal. Those now read "probe", in grey, and red
|
|
|
|
|
is kept for a session that did carry traffic and then broke. The panels also got more room between
|
|
|
|
|
them.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
0.0.13 made the certificate panel and the activity log grow and shrink together, so opening the
|
|
|
|
|
upload section no longer leaves a gap under the button.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
0.0.12 tightened the spacing in the certificate panel, and dropped a line claiming certificates
|
|
|
|
|
are read from Nginx Proxy Manager.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
0.0.11 lined up the copy buttons along the right edge on a phone, and moved the upload section
|
|
|
|
|
above the certificate picker.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
0.0.10 made the dashboard work on a phone, and dropped the tile counting the days left on your
|
|
|
|
|
certificate.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
0.0.9 moved everything the app writes into the "data" folder inside the app folder, which is
|
|
|
|
|
where the App Store expects an app to keep its state.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
0.0.8 gave the dashboard the same line as this listing, instead of describing TLS as a means.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
0.0.7 added uploading your own certificate, with the key checked against the certificate before
|
|
|
|
|
anything is stored.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
0.0.6 made a connected wallet visible while it is connected, turned the certificate picker into
|
|
|
|
|
a dropdown, and rewrote the session line in the activity log.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
0.0.5 shortened the message you get when more than one certificate was found.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
0.0.4 fixed an install that showed no dashboard at all.
|
|
|
|
|
|
|
|
|
|
developer: "WhatsNext?"
|
|
|
|
|
website: https://sc.kamenier-hamer.nl/sysop/UmbrelApps
|
|
|
|
|
dependencies:
|
|
|
|
|
- electrs
|
|
|
|
|
repo: https://sc.kamenier-hamer.nl/sysop/UmbrelApps
|
|
|
|
|
support: https://sc.kamenier-hamer.nl/sysop/UmbrelApps/issues
|
|
|
|
|
# De poort waarop umbrelOS de web-UI van deze app aanbiedt, niet de TLS-poort.
|
|
|
|
|
# Die staat in docker-compose.yml en is 50022.
|
|
|
|
|
port: 3850
|
|
|
|
|
# Leeg laten bij een nieuw pakket; de plaatjes doet het store-team zelf.
|
|
|
|
|
gallery: []
|
|
|
|
|
path: ""
|
|
|
|
|
submitter: "WhatsNext?"
|
|
|
|
|
submission: https://sc.kamenier-hamer.nl/sysop/UmbrelApps
|
|
|
|
|
|
|
|
|
|
# ── Hieronder staat wat de voorgeschreven volgorde niet noemt ────────────────
|
|
|
|
|
#
|
|
|
|
|
# defaultUsername en defaultPassword stonden hier met een lege waarde en zijn
|
|
|
|
|
# eruit. Deze app heeft geen eigen inlog; de app_proxy van umbrelOS zet er zijn
|
|
|
|
|
# eigen voor. Een leeg veld zegt niets en suggereert dat er iets te vullen valt.
|
|
|
|
|
|
|
|
|
|
# Wat niet in de back-up hoeft. Paden zijn relatief aan de app-datamap en
|
|
|
|
|
# ondersteunen een jokerteken; nagekeken in app.ts van umbreld op 20-08-2026.
|
|
|
|
|
#
|
|
|
|
|
# Alleen de twee die groeien of elke minuut veranderen. Wat er bewust NIET bij
|
|
|
|
|
# staat is data/runtime/config: daar zit de certificaatkeuze van de gebruiker, en
|
|
|
|
|
# die is het enige in deze map dat niet opnieuw te bedenken is.
|
|
|
|
|
backupIgnore:
|
|
|
|
|
- data/runtime/stream.log
|
|
|
|
|
- data/runtime/status.json
|
|
|
|
|
|
|
|
|
|
# Het icoon hoort bij een eigen store en moet bij inlevering in de officiele
|
|
|
|
|
# store juist weg: die host iconen apart. Daarom staat het als laatste, want dan
|
|
|
|
|
# is dit de enige regel die eruit moet en blijft de rest letterlijk op orde.
|
|
|
|
|
icon: https://sc.kamenier-hamer.nl/sysop/UmbrelApps/raw/branch/main/whatsnext-electrum-gate/icon.png
|