Ktistec in the pasture

Ktistec 3.13.0 (peers/ktistec.sh): built from its tag (images/ktistec, its own Dockerfile pinned), set up through its
API. scenarios/ktistec.sh, 27 checks, twice in a row: follows, posts, replies, likes and boosts with their undos both
ways, its poll and alice's vote, FEP-044f quotes both ways, edits and deletions both ways, the unfollow, statistics. It
is driven through the part of the Mastodon API it speaks and its own outbox API, and read from a copy of its SQLite
database, since its API counts no likes or boosts. CLAUDE.md also asks that a change to what PrivaPub sends be run
against every peer before it is committed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
This commit is contained in:
thepraandClaude Opus 5.5 committed 2026-10-06 14:09:29 +02:00
1 parent b478049303
commit 9872b78677
7 files changed
+218

No files matched your search

+38
View File
@@ -0,0 +1,38 @@
# Ktistec 3.13.0 (Crystal, SQLite): a small ActivityPub server with its own JSON API. Built from its tag
# (images/ktistec), as ktistec.test; its static OpenSSL reads /etc/ssl/cert.pem, where the pasture's bundle goes. The
# server's name and its first account (ktuser) are given through its setup API, which takes them unauthenticated until
# there is one; a script signs in on /sessions, whose answer carries the bearer token both its APIs take (its own, and
# the part of Mastodon's it speaks).
KTISTEC_IMAGE=${KTISTEC_IMAGE:-localhost/pasture-ktistec:3.13.0}
KTISTEC_PASSWORD=Ktistec-Pasture-1
ktistec_up() {
podman image exists "$KTISTEC_IMAGE" || podman build -q -t "$KTISTEC_IMAGE" "$here/images/ktistec" >/dev/null
mkdir -p "$here/.state/ktistec"
podman volume exists pasture-ktistec || podman volume create --label pasture=1 pasture-ktistec >/dev/null
podman run -d --replace --name pasture-ktistec --label pasture=1 --network $net -v pasture-ktistec:/db \
-v "$ca/bundle.pem:/etc/ssl/cert.pem:z,ro" -v "$ca/bundle.pem:/etc/ssl/certs/ca-certificates.crt:z,ro" "$KTISTEC_IMAGE" >/dev/null
for _ in $(seq 1 60); do
site ktistec.test -s -o /dev/null -w '%{http_code}' https://ktistec.test:6443/ 2>/dev/null | grep -qE '200|302' && break
sleep 1
done
# its setup, once: the server's address and name, then its first account
kt -o /dev/null -X POST https://ktistec.test:6443/ -d '{"host":"https://ktistec.test","site":"Pasture Ktistec"}'
# (every field is required, summary too: a missing one sends the setup back to its first page)
kt -o /dev/null -X POST https://ktistec.test:6443/ -d "{\"username\":\"ktuser\",\"password\":\"$KTISTEC_PASSWORD\",\"name\":\"ktuser\",\"summary\":\"Ktistec in the pasture\",\"language\":\"en\",\"timezone\":\"UTC\",\"auto_approve_followers\":true}"
ktistec_token > "$here/.state/ktistec/ktuser.token"
# quotes approved without asking: with manual approval on, Ktistec's posts name only their author in canQuote and offer
# no manualApproval, so no other server may even ask. (Its settings are written whole: a flag left out is turned off.)
kt -o /dev/null -X POST https://ktistec.test:6443/settings/actor -H "Authorization: Bearer $(cat "$here/.state/ktistec/ktuser.token")" \
-d '{"manually_approve_quotes":false,"auto_approve_followers":true}'
echo "ktistec: https://ktistec.test:6443"
}
# kt <curl args...>: Ktistec's JSON API
kt() { site ktistec.test -s -H 'Content-Type: application/json' -H 'Accept: application/json' "$@"; }
# ktistec_token [user]: the bearer token of a signed-in session (ktuser's)
ktistec_token() {
kt -X POST https://ktistec.test:6443/sessions -d "{\"username\":\"${1:-ktuser}\",\"password\":\"$KTISTEC_PASSWORD\"}" \
| python3 -c 'import json, sys; d = json.load(sys.stdin); print(d.get("jwt") or d.get("token") or "")' 2>/dev/null
}