De app losgetrokken van een enkele client
Op verzoek van de gebruiker is dit geen app meer over de labels van een bepaalde wallet, maar wat het technisch al was: een relay voor apps die op Evolu gebouwd zijn. De tagline, de beschrijving, de releaseNotes en de statuspagina noemen geen enkele client meer, en category gaat van bitcoin naar files, waar de officiele store ook synchronisatie tussen apparaten onderbrengt. De tekst leunt op wat Evolu zelf schrijft en niet op een verzinsel: local-first, end-to-end versleuteld voordat het je apparaat verlaat, en een relay die alleen een owner id, tijdstempels en gevulde blobs ziet. Daar staat expliciet bij wat zelf hosten wel en niet verandert, want geheimer wordt de data er niet van; wie de versleutelde kopie bewaart en wie kan zien dat je synchroniseert wel. De tegenwerping is niet weerlegd maar geaccepteerd, en dat staat als zodanig in open punt 7: "Evolu Relay" zegt een Umbrel-gebruiker niets, terwijl de labels van een bekende wallet een concrete reden zijn om te installeren. Vindbaarheid inleveren is hier een keuze. Blijkt het te knellen, dan is daar terug te lezen waarom. In het Nederlandse codecommentaar blijft de historische toelichting staan, want die legt uit waarom de relay van Trezor eruit is gegaan. Alleen de regels die de app beschrijven zijn generiek gemaakt. Tests: test_appstore_vorm 34 goed, 0 fout. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -201,7 +201,16 @@
|
|||||||
weg uit [PLAN.md](PLAN.md) §4b weer actueel: de rij met de hand in de database zetten.
|
weg uit [PLAN.md](PLAN.md) §4b weer actueel: de rij met de hand in de database zetten.
|
||||||
**Moment:** zodra **Proefopstelling** de registratievraag beantwoordt · **Eigenaar:** volgt uit dat plan
|
**Moment:** zodra **Proefopstelling** de registratievraag beantwoordt · **Eigenaar:** volgt uit dat plan
|
||||||
|
|
||||||
7. **Hoe positioneren we de app als het de generieke Evolu-relay wordt?**
|
7. **Hoe positioneren we de app als het de generieke Evolu-relay wordt?** - **beslist op 28-08-2026 door
|
||||||
|
de gebruiker: helemaal generiek.** De app-tekst noemt Trezor niet meer, `category` gaat van `bitcoin`
|
||||||
|
naar `files`, en de pagina spreekt over "your app" in plaats van één cliënt. De onderbouwing komt van
|
||||||
|
Evolu zelf: local-first, end-to-end versleuteld, en een relay die alleen een `OwnerId`, tijdstempels en
|
||||||
|
gevulde blobs ziet.
|
||||||
|
|
||||||
|
**De tegenwerping hieronder is niet weerlegd maar geaccepteerd**, en dat hoort erbij: "Evolu Relay" zegt
|
||||||
|
een Umbrel-gebruiker niets, terwijl de labels van Trezor Suite een concrete reden zijn om te
|
||||||
|
installeren. Vindbaarheid inleveren is hier een keuze en geen vergissing. Blijkt het later te knellen,
|
||||||
|
dan is dit de plek om terug te lezen waarom.
|
||||||
Opgemerkt door de gebruiker op 25-08-2026, meteen na punt 6: verpakken we niet langer iets van Trezor maar
|
Opgemerkt door de gebruiker op 25-08-2026, meteen na punt 6: verpakken we niet langer iets van Trezor maar
|
||||||
een relay van Evolu, dan hoeft de app-tekst niet meer over Trezor te gaan.
|
een relay van Evolu, dan hoeft de app-tekst niet meer over Trezor te gaan.
|
||||||
|
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
# ═══════════════════════════════════════════════════════════════════════════════
|
# ═══════════════════════════════════════════════════════════════════════════════
|
||||||
# Evolu Relay - je eigen sync-server voor de labels van Trezor Suite.
|
# Evolu Relay - je eigen sync-server voor apps die op Evolu gebouwd zijn.
|
||||||
#
|
#
|
||||||
# Drie containers: de relay, een agent voor de statuspagina, en nginx die die
|
# Drie containers: de relay, een agent voor de statuspagina, en nginx die die
|
||||||
# pagina serveert. Geen Postgres en geen quota-manager meer; die hoorden bij de
|
# pagina serveert. Geen Postgres en geen quota-manager meer; die hoorden bij de
|
||||||
@@ -14,8 +14,8 @@
|
|||||||
# relay daar en moest de inlog dus uit, waardoor een statuspagina net zo
|
# relay daar en moest de inlog dus uit, waardoor een statuspagina net zo
|
||||||
# onbeschermd zou zijn als de relay zelf;
|
# onbeschermd zou zijn als de relay zelf;
|
||||||
# - de RELAY publiceert zijn eigen poort, waar Zoraxy met TLS naartoe wijst.
|
# - de RELAY publiceert zijn eigen poort, waar Zoraxy met TLS naartoe wijst.
|
||||||
# Trezor Suite is geen browser met een sessiecookie en zou achter de inlog een
|
# een sync-cliënt is geen browser met een sessiecookie en zou achter de inlog
|
||||||
# inlogpagina krijgen in plaats van de relay.
|
# een inlogpagina krijgen in plaats van de relay.
|
||||||
#
|
#
|
||||||
# Dat is hetzelfde patroon als Electrum Gate in deze store: de web-UI via de
|
# Dat is hetzelfde patroon als Electrum Gate in deze store: de web-UI via de
|
||||||
# proxy, het protocol op een eigen poort. Zie PLAN.md §4h.
|
# proxy, het protocol op een eigen poort. Zie PLAN.md §4h.
|
||||||
@@ -93,7 +93,7 @@ services:
|
|||||||
# netwerk. De vorm <app-id>_<service>_1 is uniek per app.
|
# netwerk. De vorm <app-id>_<service>_1 is uniek per app.
|
||||||
RELAY_HOST: whatsnext-evolu-relay_relay_1
|
RELAY_HOST: whatsnext-evolu-relay_relay_1
|
||||||
RELAY_PORT: "4000"
|
RELAY_PORT: "4000"
|
||||||
# Alleen om op de pagina het adres te tonen dat je in Trezor Suite invult.
|
# Alleen om op de pagina het adres te tonen dat je in je cliënt invult.
|
||||||
# Moet gelijk zijn aan de hostpoort hierboven.
|
# Moet gelijk zijn aan de hostpoort hierboven.
|
||||||
RELAY_PUBLIC_PORT: "3852"
|
RELAY_PUBLIC_PORT: "3852"
|
||||||
RELAY_API_PORT: "8000"
|
RELAY_API_PORT: "8000"
|
||||||
|
|||||||
@@ -219,7 +219,7 @@ footer { color: var(--text-ter); font-size: 0.78rem; text-align: center; margin-
|
|||||||
<span class="spacer"></span>
|
<span class="spacer"></span>
|
||||||
<button class="theme-toggle" id="theme">Light</button>
|
<button class="theme-toggle" id="theme">Light</button>
|
||||||
</header>
|
</header>
|
||||||
<p class="sub">Your own sync server for Trezor Suite labels. Nothing leaves your machine.</p>
|
<p class="sub">Encrypted sync and backup for your local-first apps, on hardware you own.</p>
|
||||||
|
|
||||||
<div class="notice" id="notice"></div>
|
<div class="notice" id="notice"></div>
|
||||||
|
|
||||||
@@ -242,12 +242,12 @@ footer { color: var(--text-ter); font-size: 0.78rem; text-align: center; margin-
|
|||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="card">
|
<div class="card">
|
||||||
<h2>Point Trezor Suite here</h2>
|
<h2>Point your app here</h2>
|
||||||
<div class="url-box" id="relay-url">-</div>
|
<div class="url-box" id="relay-url">-</div>
|
||||||
<p class="hint">
|
<p class="hint">
|
||||||
In Trezor Suite, open the developer settings and set the custom relay URL. Leave the quota manager
|
Set this as the sync address in your Evolu app. Some apps only offer the field in their developer
|
||||||
URL empty: Suite ignores it once a custom relay is set. The address must start with http or https;
|
or advanced settings. The address has to start with http or https, not ws, even though the
|
||||||
Suite rejects ws.
|
connection itself is a websocket: the client works that out on its own.
|
||||||
</p>
|
</p>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
|
|||||||
@@ -9,69 +9,72 @@
|
|||||||
# andere app af. Een leeg veld zou suggereren dat er iets te kiezen valt.
|
# andere app af. Een leeg veld zou suggereren dat er iets te kiezen valt.
|
||||||
manifestVersion: 1
|
manifestVersion: 1
|
||||||
id: whatsnext-evolu-relay
|
id: whatsnext-evolu-relay
|
||||||
category: bitcoin
|
category: files
|
||||||
name: Evolu Relay
|
name: Evolu Relay
|
||||||
version: "0.2.1"
|
version: "0.2.1"
|
||||||
tagline: Sync your Trezor Suite labels through your own machine
|
tagline: Encrypted sync and backup for your local-first apps
|
||||||
description: >-
|
description: >-
|
||||||
Trezor Suite can sync the labels and account names you give your addresses across your
|
Local-first apps keep your data on your own device and work whether or not you have a
|
||||||
devices. By default that runs through a server operated by Trezor. This app runs that
|
connection. A relay is what lets a second device catch up: it holds the encrypted changes
|
||||||
server on your Umbrel instead, so the sync goes through a machine you own.
|
until your other devices come online. This app runs that relay on your Umbrel, so the copy
|
||||||
|
in the middle sits on hardware you own.
|
||||||
|
|
||||||
|
|
||||||
The data is end to end encrypted on your device before it leaves, so Trezor cannot read
|
It is the relay from the Evolu project, taken straight from the package they publish and not
|
||||||
your labels either way. What self-hosting changes is who holds the encrypted copy and who
|
reimplemented here. Any app built on Evolu can use it.
|
||||||
can see that you are syncing at all.
|
|
||||||
|
|
||||||
|
|
||||||
This runs the relay from the Evolu project, the sync layer Trezor Suite is built on, taken
|
Your data is encrypted on your device before it leaves. The relay holds encrypted blobs,
|
||||||
straight from the package they publish. Nothing about it is reimplemented here. What this app
|
padded so their size says nothing, and never has the key. What it can see is an owner id,
|
||||||
adds is the part a self-hosted relay needs and an open one does not: control over who may use
|
which identifies data without identifying you, along with timestamps and the addresses that
|
||||||
it.
|
connect. Self-hosting does not make the data more secret than it already is; what it changes
|
||||||
|
is who keeps the encrypted copy, who can see that you are syncing at all, and whether anyone
|
||||||
|
can pull the service out from under you.
|
||||||
|
|
||||||
|
|
||||||
The tile opens a status page. It shows whether the relay is running, how much it stores, and
|
What this app adds is the part a self-hosted relay needs and a public one does not: control
|
||||||
which devices are allowed. New devices are accepted one at a time: the first owner that
|
over who may use it. New owners are accepted one at a time. The first one that connects is
|
||||||
connects is remembered, and you close the door again once your own devices are paired. Any
|
remembered, and you close the door again once your own devices are paired; anything new is
|
||||||
owner can be blocked or removed later from that same page.
|
refused until you open it. Any owner can be blocked or removed later.
|
||||||
|
|
||||||
|
|
||||||
Point Trezor Suite at this Umbrel to use it. Away from home you will need a way in, such as
|
The tile opens a status page behind your umbrelOS login, showing whether the relay is
|
||||||
Tailscale or a reverse proxy with your own domain.
|
running, how much it holds, when it was last written to, and which owners are allowed. Point
|
||||||
|
your app at the address shown there. Away from home you will need a way in, such as Tailscale
|
||||||
|
or a reverse proxy with your own domain.
|
||||||
releaseNotes: >-
|
releaseNotes: >-
|
||||||
Fixes a status page that alternated between working and showing an error. It reached its helper by a
|
Fixes a status page that alternated between working and showing an error. It reached its helper by a
|
||||||
short name that another app in this store uses as well, so about half of its requests ended up at the
|
short name that another app in this store uses as well, so about half of its requests ended up at the
|
||||||
wrong app. It now uses a name that is unique to this one.
|
wrong app. It now uses a name that is unique to this one.
|
||||||
|
|
||||||
|
|
||||||
|
This release also drops the wording that tied the app to one particular client. It is a general
|
||||||
|
purpose Evolu relay: any app built on Evolu can use it.
|
||||||
|
|
||||||
|
|
||||||
Earlier releases:
|
Earlier releases:
|
||||||
|
|
||||||
|
|
||||||
0.2.0 was a different relay, and a much smaller app. 0.0.2 packaged the relay Trezor runs for their own
|
0.2.0 replaced the relay this app shipped with. Until 0.0.2 it packaged a vendor's own deployment,
|
||||||
hosted service, with a quota manager and a PostgreSQL database beside it. That combination
|
which came with a quota manager and a PostgreSQL database and could not work outside that vendor's
|
||||||
cannot work on your own machine: Suite skips the quota manager as soon as you point it at a
|
service: clients skip the quota manager as soon as you point them at a relay of your own, while
|
||||||
relay of your own, while that relay refuses every owner the quota manager never registered.
|
that relay refuses every owner the quota manager never registered. 0.2.0 uses the relay from the
|
||||||
|
Evolu project instead. Measured, not assumed: a client synced to it and the data arrived. Three
|
||||||
|
containers became one relay plus a status page, and the database and its password are gone.
|
||||||
|
|
||||||
|
|
||||||
This release uses the relay from the Evolu project instead, which Trezor Suite talks to
|
0.2.0 also added the status page behind your umbrelOS login, and control over who may sync.
|
||||||
directly. Measured, not assumed: Suite sent labels to it and they arrived. The database and
|
|
||||||
the quota manager are gone, and three containers became one relay plus a status page.
|
|
||||||
|
|
||||||
|
|
||||||
New: a status page behind your umbrelOS login, and control over who may sync. The first owner
|
Not verified yet: reading back from a second device, and whether every client platform can use a
|
||||||
that connects is remembered and accepted; after that you close the door, and anything new is
|
relay of your own.
|
||||||
refused until you open it again.
|
|
||||||
|
|
||||||
|
|
||||||
Not verified yet: reading back from a second device, and whether the iOS app can use a relay
|
|
||||||
of your own at all.
|
|
||||||
developer: "WhatsNext?"
|
developer: "WhatsNext?"
|
||||||
website: https://sc.kamenier-hamer.nl/sysop/UmbrelApps
|
website: https://sc.kamenier-hamer.nl/sysop/UmbrelApps
|
||||||
repo: https://sc.kamenier-hamer.nl/sysop/UmbrelApps
|
repo: https://sc.kamenier-hamer.nl/sysop/UmbrelApps
|
||||||
support: https://sc.kamenier-hamer.nl/sysop/UmbrelApps/issues
|
support: https://sc.kamenier-hamer.nl/sysop/UmbrelApps/issues
|
||||||
# De poort waarop umbrelOS deze app aanbiedt. Sinds 0.1.0 is dat de STATUSPAGINA
|
# De poort waarop umbrelOS deze app aanbiedt. Sinds 0.1.0 is dat de STATUSPAGINA
|
||||||
# en niet de relay: de app-proxy zet er de inlog van umbrelOS voor, en daar hoort
|
# en niet de relay: de app-proxy zet er de inlog van umbrelOS voor, en daar hoort
|
||||||
# een pagina wel achter en een relay niet. Trezor Suite wijst naar 3852, die de
|
# een pagina wel achter en een relay niet. De cliënt wijst naar 3852, die de
|
||||||
# relay zelf publiceert. Zie docker-compose.yml en het plan Umbrelapp, PLAN.md §4h.
|
# relay zelf publiceert. Zie docker-compose.yml en het plan Umbrelapp, PLAN.md §4h.
|
||||||
#
|
#
|
||||||
# Niet 4000, de eigen poort van de relay: die is een veelgebruikte poort en een
|
# Niet 4000, de eigen poort van de relay: die is een veelgebruikte poort en een
|
||||||
|
|||||||
Reference in New Issue
Block a user