PieFed joins the pasture; the instance actor answers at the root

PieFed 1.7.17 (dockurr's image of the release) runs in the pasture with its
Celery worker on the shared Postgres and Redis, and scenarios/piefed.sh
checks it both ways: 29 checks, communities, titled threads, comments, votes
up and down, a community poll and a vote in it, private messages, a
moderator's lock, unlock and removal, the unfollow and statistics.

What it showed:
- PieFed sends a community's announces to the inbox of the Application at a
  peer's root (as Lemmy serves its site actor) and to /inbox otherwise.
  PrivaPub answered 404 at its root, so every announce went to an /inbox it
  does not have. The instance actor now answers at / for ActivityPub
  requests, unsigned under SecureMode as at its own address.
- PieFed keeps serving a thread its moderator removed, so the removal could
  never be checked against the post's origin. A community on the post's own
  server now speaks for it; one elsewhere still waits for the origin to say
  the post is gone.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
This commit is contained in:
thepraandClaude Opus 5.5 committed 2026-10-05 15:44:13 +02:00
1 parent 0646de22bd
commit 47d6e22988
12 files changed
+304 -17

No files matched your search

+65
View File
@@ -0,0 +1,65 @@
# PieFed 1.7.17: a threadiverse server (communities, threads, comments, votes up and down, polls, flairs) in Flask, from
# dockurr's image of the release. The web app (gunicorn, with PieFed's own cron for its send queue) and a Celery worker
# share the pasture-piefed-media volume, on the shared Postgres (database piefed) and Redis (dbs 10 and 11). httpx
# trusts only certifi's bundle, so the pasture's is mounted over it. `flask init-db` asks for its admin on stdin
# (pfuser); its Lemmy-style API (/api/alpha) signs in with a JWT.
PIEFED_IMAGE=${PIEFED_IMAGE:-docker.io/dockurr/piefed:1.7.17}
PIEFED_PASSWORD=PieFed-Pasture-1
. "$here/peers/shared.sh"
piefed_env() {
local key="$here/.state/piefed/secret"
[ -s "$key" ] || { mkdir -p "$here/.state/piefed"; head -c 48 /dev/urandom | base64 -w0 | tr -d '/+=' > "$key"; }
cat <<ENV
SERVER_NAME=piefed.test
SECRET_KEY=$(cat "$key")
DATABASE_URL=postgresql+psycopg2://pasture:pasture@postgres:5432/piefed
CACHE_TYPE=RedisCache
CACHE_REDIS_URL=redis://redis:6379/10
CELERY_BROKER_URL=redis://redis:6379/11
RESULT_BACKEND=redis://redis:6379/11
ENABLE_ALPHA_API=true
CORS_ALLOW_ORIGIN=*
REDIS_MEMORY_LIMIT=-1
VOTE_QUOTA=100000
REQUESTS_CA_BUNDLE=/ca/bundle.pem
SSL_CERT_FILE=/ca/bundle.pem
ENV
}
piefed_up() {
shared_postgres_up
shared_redis_up
pg_db piefed
mkdir -p "$here/.state/piefed"
piefed_env > "$here/.state/piefed/env"
podman volume exists pasture-piefed-media || podman volume create --label pasture=1 pasture-piefed-media >/dev/null
local common=(--network $net --label pasture=1 --env-file "$here/.state/piefed/env" -v pasture-piefed-media:/app/app/static/media
-v "$ca/bundle.pem:/ca/bundle.pem:z,ro" -v "$ca/bundle.pem:/venv/lib/python3.13/site-packages/certifi/cacert.pem:z,ro")
podman run -d --replace --name pasture-piefed "${common[@]}" -e CRON=true "$PIEFED_IMAGE" >/dev/null
podman run -d --replace --name pasture-piefed-celery "${common[@]}" --entrypoint ./entrypoint_celery.sh "$PIEFED_IMAGE" >/dev/null
# the web app runs its migrations before gunicorn starts; init-db then sets the site up once, and drops every table
# it finds, so it waits for the last migration
for _ in $(seq 1 120); do
podman logs pasture-piefed 2>&1 | grep -q "Starting Gunicorn" && break
sleep 2
done
if ! podman exec pasture-postgres psql -U pasture -d piefed -tAc "select 1 from \"user\" where user_name = 'pfuser'" 2>/dev/null | grep -q 1; then
printf 'pfuser\npfuser@piefed.test\n%s\n' "$PIEFED_PASSWORD" | podman exec -i -e FLASK_APP=pyfedi.py pasture-piefed flask init-db >/dev/null 2>&1
podman restart pasture-piefed pasture-piefed-celery >/dev/null
fi
for _ in $(seq 1 90); do
site piefed.test -s -o /dev/null -w '%{http_code}' https://piefed.test:6443/api/alpha/site 2>/dev/null | grep -q 200 && break
sleep 2
done
piefed_settle
echo "piefed: https://piefed.test:6443"
}
# open registrations, no rate limit on its API for the pasture, and pfuser's JWT
piefed_settle() {
podman exec pasture-postgres psql -U pasture -d piefed -qc "update site set registration_mode = 'Open', enable_downvotes = true" >/dev/null 2>&1 || true
site piefed.test -s -X POST https://piefed.test:6443/api/alpha/user/login -H 'Content-Type: application/json' \
-d "{\"username\":\"pfuser\",\"password\":\"$PIEFED_PASSWORD\"}" \
| python3 -c "import sys,json; print(json.load(sys.stdin)['jwt'])" > "$here/.state/piefed.token" 2>/dev/null || true
}