Plan Eigenimage, fase 1 tot en met 3. De vier templates verhuizen naar tools/electrum-gate/ zonder extensie; daarnaast Dockerfile (nginx:1.30-alpine plus python3), entrypoint.sh (het command-blok van de compose, zonder $$) en build.sh naar het voorbeeld van Evolu Relay. Een image voor beide containers, gebouwd op de Umbrel; open punt 2 en 3 daarmee beslist. Inhoudelijk anders dan alleen verplaatst: het log_format staat in stream.conf zelf, het backend-adres komt via twee plaatshouders zonder dollarteken uit de omgeving (ook in de server-service), en de pagina haalt versie en adres uit status.json via GATE_APP_VERSION. Tests mee verhuisd en uitgebreid: entrypoint.sh en Dockerfile in plaats van het command-blok, en de tag in de compose gelijk aan VERSION in build.sh voor elke eigen image. Mutatie-getest met drie ingrepen. Nog niet gebouwd: er is hier geen Docker. De tag staat ongepind tot de eerste push; dat is fase 4 en die is van de gebruiker. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
106 lines
5.3 KiB
Markdown
106 lines
5.3 KiB
Markdown
# UmbrelApps
|
|
|
|
A community app store for [Umbrel](https://umbrel.com), store id `whatsnext`. Add it in umbrelOS under
|
|
**App Store → Community App Stores**, using the clone URL of this repository.
|
|
|
|
## Apps
|
|
|
|
### Electrum Gate
|
|
|
|
Reach your own Electrum server from outside your network, over TLS. An Electrum server speaks plain TCP;
|
|
a wallet on the road wants TLS. This app puts a proxy in between, using the certificate a reverse proxy on
|
|
the same Umbrel already manages.
|
|
|
|
Two containers, one image, built from [tools/electrum-gate/](tools/electrum-gate/) by its `build.sh`
|
|
(nginx on alpine, plus python3). The app folder holds only the compose file, the manifest, the icon and
|
|
your data.
|
|
|
|
| Container | What it does |
|
|
|-|-|
|
|
| `server` | terminates TLS on 50022 and forwards plain to the Electrum server; serves the dashboard on port 80 behind the umbrelOS app proxy |
|
|
| `agent` | same image, different command; writes `status.json` every minute, reads the certificates from the mounted folders, queries the Electrum server, and accepts the certificate choice |
|
|
|
|
The agent cannot reload nginx itself, as that would need the Docker socket and it is deliberately absent.
|
|
It writes `cert.conf` with the chosen paths and drops a flag file; the nginx container reloads itself. A
|
|
reload keeps existing wallet connections alive.
|
|
|
|
| Port | For |
|
|
|-|-|
|
|
| 50022 | TLS for Electrum wallets. **Not** the conventional 50002: Fulcrum occupies that on the host, and with Fulcrum as the backend the container would not start |
|
|
| 3850 | the web UI, through the umbrelOS app proxy |
|
|
|
|
Electrs, Fulcrum and ElectrumX all work, switchable in the umbrelOS settings: the app declares the
|
|
dependency and uses the address it is handed. Details, with sources, in
|
|
[Docs/Referenties/Umbrel-appstore-spec.md](Docs/Referenties/Umbrel-appstore-spec.md) §4.
|
|
|
|
**Tor or TLS.** The privacy win is in running your own server, and you have that the moment you do. Tor
|
|
remains the better choice for privacy; TLS wins on speed, on mobile, and on networks that block Tor. The
|
|
trade-off is written out in [Docs/Referenties/Clients.md](Docs/Referenties/Clients.md) §1.
|
|
|
|
### Evolu Relay
|
|
|
|
> **Packaged, never installed.** The manifest and compose are here; nothing has run on an Umbrel yet.
|
|
|
|
Trezor Suite syncs labels and account names between devices, and by default that runs through a server
|
|
operated by Trezor. That server is open source and called Evolu Relay. This app runs it on your own
|
|
machine. The data is end to end encrypted on the device, so self-hosting does not change that guarantee,
|
|
it only changes who holds the encrypted copy.
|
|
|
|
Three containers, two images.
|
|
|
|
| Container | What it does |
|
|
|-|-|
|
|
| `relay` | the sync relay on 4000, reached through the app proxy on 3851 |
|
|
| `quota-manager` | same image, different command; registers the storage limit the relay requires |
|
|
| `db` (`postgres:17-alpine`) | storage, under `${APP_DATA_DIR}/data/postgres` |
|
|
|
|
The app proxy runs with `PROXY_AUTH_ADD: "false"`, because Trezor Suite is not a browser with a session
|
|
cookie. That is the same pattern Umbrel's own nostr-relay app uses. The flip side: anything that can reach
|
|
port 3851 reaches the relay without signing in. What limits the damage is that the relay refuses any owner
|
|
without a storage limit registered in its database.
|
|
|
|
**Trezor publishes no image**, so it is built from their Dockerfile, pinned to a commit, by
|
|
[tools/evolu-relay/build.sh](tools/evolu-relay/build.sh). Run that before installing.
|
|
|
|
Still unverified: whether Trezor Suite accepts this address, whether the database schema creates itself,
|
|
and how an owner gets registered. See
|
|
[Docs/Referenties/Upstream-evolu-relay.md](Docs/Referenties/Upstream-evolu-relay.md).
|
|
|
|
## Documentatie
|
|
|
|
Alles staat in **[Docs/](Docs/README.md)**. Begin bij
|
|
**[Docs/CONTINUE_HERE.md](Docs/CONTINUE_HERE.md)**; dat is de index die naar de volgende stap wijst.
|
|
|
|
| Waar je heen wilt | Waar het staat |
|
|
|-|-|
|
|
| Wat er nu speelt en wat de volgende stap is | [Docs/CONTINUE_HERE.md](Docs/CONTINUE_HERE.md) |
|
|
| Wat umbrelOS van een app store verwacht | [Docs/Referenties/Umbrel-appstore-spec.md](Docs/Referenties/Umbrel-appstore-spec.md) |
|
|
| Hoe Electrum Gate vandaag in elkaar zit | [Docs/Referenties/Architectuur-huidig.md](Docs/Referenties/Architectuur-huidig.md) |
|
|
| Welke wallets hierheen kunnen wijzen, en wanneer Tor beter is | [Docs/Referenties/Clients.md](Docs/Referenties/Clients.md) |
|
|
| Wat er over de sync-server van Trezor bekend is | [Docs/Referenties/Upstream-evolu-relay.md](Docs/Referenties/Upstream-evolu-relay.md) |
|
|
| Versiegeschiedenis van Electrum Gate | [Docs/CHANGELOG-electrum-gate.md](Docs/CHANGELOG-electrum-gate.md) |
|
|
| Waar documentatie hoort | [Docs/README.md](Docs/README.md) |
|
|
|
|
## Tests
|
|
|
|
```
|
|
python tests/test_appstore_vorm.py
|
|
```
|
|
|
|
Die gaat over de store en vindt zijn apps zelf: id gelijk aan mapnaam, store-voorvoegsel, veldvolgorde in
|
|
het manifest, en een `app_proxy` die naar een bestaande service wijst. Daarnaast twee suites voor Electrum
|
|
Gate:
|
|
|
|
```
|
|
python tests/test_agent_certificates.py
|
|
```
|
|
|
|
Losse scripts, geen afhankelijkheden. Let op de regels met `OVERGESLAGEN`: die toetsen hebben de
|
|
certificaatwinkel van het besturingssysteem of netwerk nodig, en zijn dan niet bewezen.
|
|
|
|
## Licentie
|
|
|
|
De apps zijn dunne lagen om bestaande onderdelen: nginx en Alpine Linux (BSD/MIT) voor Electrum Gate, en
|
|
straks de relay van Trezor, die zijn eigen licentie houdt. Voor de verpakking zelf is nog geen licentie
|
|
gekozen.
|