Pasture: Lemmy 0.19 joins, built to trust the pasture's CA

Most of the threadiverse runs Lemmy 0.19, whose release trusts only the
roots its rustls bundles. images/lemmy19 builds 0.19.20 from its tag with
reqwest's rustls-tls-native-roots added, and the pasture runs it as
lemmy19.test. scenarios/lemmy19.sh passes 27 checks with no change to
PrivaPub (communities, threads, comments, votes, its private message,
moderation) and one known gap: 0.19 takes private messages only as
ChatMessage and answers our direct Note 400, like Mbin, so G-0008 now
covers both and waits for the owner.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
This commit is contained in:
thepraandClaude Opus 5.5 committed 2026-10-05 17:32:22 +02:00
1 parent bd5901d15e
commit a85ebd30c0
9 files changed
+197 -9

No files matched your search

+44
View File
@@ -0,0 +1,44 @@
# Lemmy 0.19.20, the version most of the threadiverse runs, as lemmy19.test: the backend alone on the shared Postgres,
# built by images/lemmy19 from its tag with reqwest also trusting the platform's roots (the release trusts only the ones
# it bundles), and given the pasture's bundle as the platform's. Its API is v3.
LEMMY19_IMAGE=${LEMMY19_IMAGE:-localhost/pasture-lemmy19:0.19.20}
. "$here/peers/shared.sh"
lemmy19_up() {
podman image exists "$LEMMY19_IMAGE" || podman build -q -t "$LEMMY19_IMAGE" "$here/images/lemmy19" >/dev/null
shared_postgres_up
pg_db lemmy19
mkdir -p "$here/.state/lemmy19"
cat > "$here/.state/lemmy19/config.hjson" <<HJSON
{
database: { uri: "postgresql://pasture:pasture@postgres:5432/lemmy19" }
hostname: "lemmy19.test"
bind: "0.0.0.0"
port: 8536
tls_enabled: true
setup: {
admin_username: "lemmyuser"
admin_password: "Lemmy-Pasture-Pass-1"
site_name: "Pasture Lemmy 0.19"
admin_email: "lemmyuser@lemmy19.test"
}
}
HJSON
podman run -d --replace --name pasture-lemmy19 --network $net --label pasture=1 -e LEMMY_CONFIG_LOCATION=/config/config.hjson \
-e SSL_CERT_FILE=/etc/ssl/certs/ca-certificates.crt -e RUST_LOG="${LEMMY_LOG:-warn}" -v "$here/.state/lemmy19:/config:z,ro" \
-v "$ca/bundle.pem:/etc/ssl/certs/ca-certificates.crt:z,ro" "$LEMMY19_IMAGE" >/dev/null
for _ in $(seq 1 90); do
site lemmy19.test -s -o /dev/null -w '%{http_code}' https://lemmy19.test:6443/api/v3/site 2>/dev/null | grep -q 200 && break
sleep 2
done
# Lemmy's default limits would throttle a scripted run; it reads them again when its site is edited
podman exec pasture-postgres psql -U pasture -d lemmy19 -qc "update local_site_rate_limit set message=100000, message_per_second=1,
post=100000, post_per_second=1, register=100000, register_per_second=1, image=100000, image_per_second=1,
comment=100000, comment_per_second=1, search=100000, search_per_second=1" >/dev/null
site lemmy19.test -s -X POST https://lemmy19.test:6443/api/v3/user/login -H 'Content-Type: application/json' \
-d '{"username_or_email":"lemmyuser","password":"Lemmy-Pasture-Pass-1"}' \
| python3 -c "import sys,json; print(json.load(sys.stdin)['jwt'])" > "$here/.state/lemmy19.token" 2>/dev/null || true
site lemmy19.test -s -o /dev/null -X PUT https://lemmy19.test:6443/api/v3/site -H "Authorization: Bearer $(cat "$here/.state/lemmy19.token")" \
-H 'Content-Type: application/json' -d '{"registration_mode":"Open","require_email_verification":false,"captcha_enabled":false}'
echo "lemmy19: https://lemmy19.test:6443"
}