A private fediverse on the workstation: PrivaPub against a real GoToSocial
Build / Build (push) Successful in 57s
Deploy / privapub.thepra.dev (push) Successful in 1m12s

tools/pasture/run.sh starts PrivaPub, GoToSocial and Mongo on one podman network behind Caddy's internal CA, and
interop.sh drives both through their own client APIs: follows (one to a locked account), posts, CW, replies, likes,
boosts, DMs, edits, deletes and unfollow. All 25 checks pass, three fresh runs in a row.

- Federation:AcceptAnyCertificate joins the two test-network switches; startup refuses all three in Production.
- WebFinger falls back to http only when AllowPlainHttp is on.
- A bootstrap logger, so a failure before the host is built is no longer silent.
- P4 is ticked in the roadmap, with what has not been run live (Lemmy, a Mastodon circle member).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012CzABvBkbcFqoHdmi8b9WB
This commit is contained in:
thepraandClaude Opus 5.5 committed 2026-10-01 13:19:16 +02:00
1 parent 31542a181e
commit 8f4d6cbdf9
12 files changed
+299 -12

No files matched your search

@@ -5,5 +5,6 @@ namespace PrivaPub.Infrastructure.Http
public bool AllowPrivateNetworks { get; set; }
public bool AllowPlainHttp { get; set; }
public bool SecureMode { get; set; }
public bool AcceptAnyCertificate { get; set; }
}
}
@@ -1,4 +1,5 @@
using System.Net;
using System.Net.Security;
using System.Net.Sockets;
namespace PrivaPub.Infrastructure.Http
@@ -12,6 +13,9 @@ namespace PrivaPub.Infrastructure.Http
{
public static SocketsHttpHandler Create(FederationOptions options) => new()
{
SslOptions = options.AcceptAnyCertificate
? new SslClientAuthenticationOptions { RemoteCertificateValidationCallback = (_, _, _, _) => true }
: new SslClientAuthenticationOptions(),
AllowAutoRedirect = false,
UseProxy = false,
UseCookies = false,