Pasture: Lemmy 0.19 joins, built to trust the pasture's CA
Most of the threadiverse runs Lemmy 0.19, whose release trusts only the roots its rustls bundles. images/lemmy19 builds 0.19.20 from its tag with reqwest's rustls-tls-native-roots added, and the pasture runs it as lemmy19.test. scenarios/lemmy19.sh passes 27 checks with no change to PrivaPub (communities, threads, comments, votes, its private message, moderation) and one known gap: 0.19 takes private messages only as ChatMessage and answers our direct Note 400, like Mbin, so G-0008 now covers both and waits for the owner. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
This commit is contained in:
1 parent
bd5901d15e
commit
a85ebd30c0
9 files changed
+197
-9
No files matched your search
@@ -0,0 +1,44 @@
|
||||
# Lemmy 0.19.20, the version most of the threadiverse runs, as lemmy19.test: the backend alone on the shared Postgres,
|
||||
# built by images/lemmy19 from its tag with reqwest also trusting the platform's roots (the release trusts only the ones
|
||||
# it bundles), and given the pasture's bundle as the platform's. Its API is v3.
|
||||
LEMMY19_IMAGE=${LEMMY19_IMAGE:-localhost/pasture-lemmy19:0.19.20}
|
||||
. "$here/peers/shared.sh"
|
||||
|
||||
lemmy19_up() {
|
||||
podman image exists "$LEMMY19_IMAGE" || podman build -q -t "$LEMMY19_IMAGE" "$here/images/lemmy19" >/dev/null
|
||||
shared_postgres_up
|
||||
pg_db lemmy19
|
||||
mkdir -p "$here/.state/lemmy19"
|
||||
cat > "$here/.state/lemmy19/config.hjson" <<HJSON
|
||||
{
|
||||
database: { uri: "postgresql://pasture:pasture@postgres:5432/lemmy19" }
|
||||
hostname: "lemmy19.test"
|
||||
bind: "0.0.0.0"
|
||||
port: 8536
|
||||
tls_enabled: true
|
||||
setup: {
|
||||
admin_username: "lemmyuser"
|
||||
admin_password: "Lemmy-Pasture-Pass-1"
|
||||
site_name: "Pasture Lemmy 0.19"
|
||||
admin_email: "lemmyuser@lemmy19.test"
|
||||
}
|
||||
}
|
||||
HJSON
|
||||
podman run -d --replace --name pasture-lemmy19 --network $net --label pasture=1 -e LEMMY_CONFIG_LOCATION=/config/config.hjson \
|
||||
-e SSL_CERT_FILE=/etc/ssl/certs/ca-certificates.crt -e RUST_LOG="${LEMMY_LOG:-warn}" -v "$here/.state/lemmy19:/config:z,ro" \
|
||||
-v "$ca/bundle.pem:/etc/ssl/certs/ca-certificates.crt:z,ro" "$LEMMY19_IMAGE" >/dev/null
|
||||
for _ in $(seq 1 90); do
|
||||
site lemmy19.test -s -o /dev/null -w '%{http_code}' https://lemmy19.test:6443/api/v3/site 2>/dev/null | grep -q 200 && break
|
||||
sleep 2
|
||||
done
|
||||
# Lemmy's default limits would throttle a scripted run; it reads them again when its site is edited
|
||||
podman exec pasture-postgres psql -U pasture -d lemmy19 -qc "update local_site_rate_limit set message=100000, message_per_second=1,
|
||||
post=100000, post_per_second=1, register=100000, register_per_second=1, image=100000, image_per_second=1,
|
||||
comment=100000, comment_per_second=1, search=100000, search_per_second=1" >/dev/null
|
||||
site lemmy19.test -s -X POST https://lemmy19.test:6443/api/v3/user/login -H 'Content-Type: application/json' \
|
||||
-d '{"username_or_email":"lemmyuser","password":"Lemmy-Pasture-Pass-1"}' \
|
||||
| python3 -c "import sys,json; print(json.load(sys.stdin)['jwt'])" > "$here/.state/lemmy19.token" 2>/dev/null || true
|
||||
site lemmy19.test -s -o /dev/null -X PUT https://lemmy19.test:6443/api/v3/site -H "Authorization: Bearer $(cat "$here/.state/lemmy19.token")" \
|
||||
-H 'Content-Type: application/json' -d '{"registration_mode":"Open","require_email_verification":false,"captcha_enabled":false}'
|
||||
echo "lemmy19: https://lemmy19.test:6443"
|
||||
}
|
||||
Reference in new issue
Block a user