Plan Eigenimage, fase 5, op keuze van de gebruiker: een image met de relay erbij en geen tweede recept. agent.py, nginx.conf en index.html verhuizen naar tools/evolu-relay/ naast src/; de Dockerfile blijft op node:24-slim en haalt nginx en python3 uit apt. Drie containers uit een image: de relay als node via de compose, de agent en nginx als root. Anders dan alleen verplaatst: user www-data in nginx.conf (Debian heeft geen gebruiker nginx), geen USER meer in de image, de versie in de kop via api/status met RELAY_APP_VERSION. VERSION 0.6.0, manifest 0.6.0, drie keer dezelfde tag in de compose, ongepind tot de eerste push. Tests mee verhuisd; de vormtest toetst de drie tags tegen VERSION. Niet gebouwd: er is hier geen Docker. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
99 lines
5.1 KiB
Markdown
99 lines
5.1 KiB
Markdown
# UmbrelApps
|
|
|
|
A community app store for [Umbrel](https://umbrel.com), store id `whatsnext`. Add it in umbrelOS under
|
|
**App Store → Community App Stores**, using the clone URL of this repository.
|
|
|
|
## Apps
|
|
|
|
### Electrum Gate
|
|
|
|
Reach your own Electrum server from outside your network, over TLS. An Electrum server speaks plain TCP;
|
|
a wallet on the road wants TLS. This app puts a proxy in between, using the certificate a reverse proxy on
|
|
the same Umbrel already manages.
|
|
|
|
Two containers, one image, built from [tools/electrum-gate/](tools/electrum-gate/) by its `build.sh`
|
|
(nginx on alpine, plus python3). The app folder holds only the compose file, the manifest, the icon and
|
|
your data.
|
|
|
|
| Container | What it does |
|
|
|-|-|
|
|
| `server` | terminates TLS on 50022 and forwards plain to the Electrum server; serves the dashboard on port 80 behind the umbrelOS app proxy |
|
|
| `agent` | same image, different command; writes `status.json` every minute, reads the certificates from the mounted folders, queries the Electrum server, and accepts the certificate choice |
|
|
|
|
The agent cannot reload nginx itself, as that would need the Docker socket and it is deliberately absent.
|
|
It writes `cert.conf` with the chosen paths and drops a flag file; the nginx container reloads itself. A
|
|
reload keeps existing wallet connections alive.
|
|
|
|
| Port | For |
|
|
|-|-|
|
|
| 50022 | TLS for Electrum wallets. **Not** the conventional 50002: Fulcrum occupies that on the host, and with Fulcrum as the backend the container would not start |
|
|
| 3850 | the web UI, through the umbrelOS app proxy |
|
|
|
|
Electrs, Fulcrum and ElectrumX all work, switchable in the umbrelOS settings: the app declares the
|
|
dependency and uses the address it is handed. Details, with sources, in
|
|
[Docs/Referenties/Umbrel-appstore-spec.md](Docs/Referenties/Umbrel-appstore-spec.md) §4.
|
|
|
|
**Tor or TLS.** The privacy win is in running your own server, and you have that the moment you do. Tor
|
|
remains the better choice for privacy; TLS wins on speed, on mobile, and on networks that block Tor. The
|
|
trade-off is written out in [Docs/Referenties/Clients.md](Docs/Referenties/Clients.md) §1.
|
|
|
|
### Evolu Relay
|
|
|
|
Trezor Suite syncs labels and account names between devices, and by default that runs through a server
|
|
operated by Trezor. That server is built on Evolu, and its relay is published as an npm package. This app
|
|
runs that relay on your own machine, with an owner allowlist around it. The data is end to end encrypted
|
|
on the device, so self-hosting does not change that guarantee, it only changes who holds the encrypted
|
|
copy.
|
|
|
|
Three containers, one image, built from [tools/evolu-relay/](tools/evolu-relay/) by its `build.sh`
|
|
(node on Debian slim, plus nginx and python3). The app folder holds only the compose file, the manifest,
|
|
the icon and your data.
|
|
|
|
| Container | What it does |
|
|
|-|-|
|
|
| `relay` | the sync relay, published on host port 3852; our `src/index.js` around `@evolu/nodejs`, adding the allowlist |
|
|
| `agent` | same image, different command; serves the status API and drops commands from the page into a mailbox the relay empties |
|
|
| `server` | same image; nginx serving the status page on port 80 behind the umbrelOS app proxy, with its sign-in |
|
|
|
|
The relay publishes its own port because a sync client is not a browser with a session cookie; the page
|
|
sits behind the app proxy because it is. New owners are admitted only while a two-minute learning window
|
|
is open on the page; everyone else is refused and listed, so you can allow them by hand.
|
|
|
|
## Documentatie
|
|
|
|
Alles staat in **[Docs/](Docs/README.md)**. Begin bij
|
|
**[Docs/CONTINUE_HERE.md](Docs/CONTINUE_HERE.md)**; dat is de index die naar de volgende stap wijst.
|
|
|
|
| Waar je heen wilt | Waar het staat |
|
|
|-|-|
|
|
| Wat er nu speelt en wat de volgende stap is | [Docs/CONTINUE_HERE.md](Docs/CONTINUE_HERE.md) |
|
|
| Wat umbrelOS van een app store verwacht | [Docs/Referenties/Umbrel-appstore-spec.md](Docs/Referenties/Umbrel-appstore-spec.md) |
|
|
| Hoe Electrum Gate vandaag in elkaar zit | [Docs/Referenties/Architectuur-huidig.md](Docs/Referenties/Architectuur-huidig.md) |
|
|
| Welke wallets hierheen kunnen wijzen, en wanneer Tor beter is | [Docs/Referenties/Clients.md](Docs/Referenties/Clients.md) |
|
|
| Wat er over de sync-server van Trezor bekend is | [Docs/Referenties/Upstream-evolu-relay.md](Docs/Referenties/Upstream-evolu-relay.md) |
|
|
| Versiegeschiedenis van Electrum Gate | [Docs/CHANGELOG-electrum-gate.md](Docs/CHANGELOG-electrum-gate.md) |
|
|
| Waar documentatie hoort | [Docs/README.md](Docs/README.md) |
|
|
|
|
## Tests
|
|
|
|
```
|
|
python tests/test_appstore_vorm.py
|
|
```
|
|
|
|
Die gaat over de store en vindt zijn apps zelf: id gelijk aan mapnaam, store-voorvoegsel, veldvolgorde in
|
|
het manifest, en een `app_proxy` die naar een bestaande service wijst. Daarnaast twee suites voor Electrum
|
|
Gate:
|
|
|
|
```
|
|
python tests/test_agent_certificates.py
|
|
```
|
|
|
|
Losse scripts, geen afhankelijkheden. Let op de regels met `OVERGESLAGEN`: die toetsen hebben de
|
|
certificaatwinkel van het besturingssysteem of netwerk nodig, en zijn dan niet bewezen.
|
|
|
|
## Licentie
|
|
|
|
De apps zijn dunne lagen om bestaande onderdelen: nginx en Alpine Linux (BSD/MIT) voor Electrum Gate, en
|
|
straks de relay van Trezor, die zijn eigen licentie houdt. Voor de verpakking zelf is nog geen licentie
|
|
gekozen.
|