Relays: PrivaPub reads from the relays its configuration names

Federation:Relays names relays by their actor (or inbox) address; the instance actor follows Public at each, as Mastodon
subscribes, a minute after start and every six hours (asked again a day after no answer or a refusal, undone when a
relay is no longer named). What an accepted relay passes on comes to the federated timeline and nobody's home: a public
post it forwards (Activity-Relay), read again from its origin like any forwarded post, and a post it announces
(aode-relay), kept as its author's and never as the relay's boost. Nothing of a persona's is sent to a relay; sending
public posts there waits for the owner.

The pasture gains both relays (peers/relay.sh, peers/aoderelay.sh) and scenarios/relay.sh, 13 checks. The village
backlog is clean: 2574 checks pass, one known gap (Misskey's).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
This commit is contained in:
thepraandClaude Opus 5.5 committed 2026-10-05 23:11:59 +02:00
1 parent 1c7d1ece9c
commit f6fc0c535c
22 files changed
+542 -24

No files matched your search

+21
View File
@@ -0,0 +1,21 @@
# aode-relay 0.3.129 (asonix): a relay that takes both kinds of subscription (Public, as Mastodon follows, or its actor,
# as LitePub does) and passes posts on as its own Announce, as aoderelay.test. Unrestricted, so anyone may subscribe;
# its state is in its own sled database. Its TLS client reads the system's roots, over which the pasture's bundle goes.
AODERELAY_IMAGE=${AODERELAY_IMAGE:-docker.io/asonix/relay:0.3.129}
aoderelay_up() {
podman volume exists pasture-aoderelay || podman volume create --label pasture=1 pasture-aoderelay >/dev/null
podman run -d --replace --name pasture-aoderelay --label pasture=1 --network $net -v pasture-aoderelay:/var/lib/aode-relay:U \
-v "$ca/bundle.pem:/etc/ssl/certs/ca-certificates.crt:z,ro" \
-e HOSTNAME=aoderelay.test -e ADDR=0.0.0.0 -e PORT=8080 -e HTTPS=true -e RESTRICTED_MODE=false -e VALIDATE_SIGNATURES=true \
-e SLED_PATH=/var/lib/aode-relay/sled -e API_TOKEN=pasture-aoderelay-token -e PRETTY_LOG=false \
$AODERELAY_IMAGE >/dev/null
for _ in $(seq 1 60); do
site aoderelay.test -s -o /dev/null -w '%{http_code}' https://aoderelay.test:6443/actor 2>/dev/null | grep -q 200 && break
sleep 1
done
echo "aoderelay: https://aoderelay.test:6443"
}
# aoderelay_connected: the hosts subscribed to it, from its admin API
aoderelay_connected() { site aoderelay.test -s https://aoderelay.test:6443/api/v1/admin/connected -H 'X-Api-Token: pasture-aoderelay-token' | j "print('\n'.join(d.get('connected_actors', d) if isinstance(d, dict) else d))"; }
+37
View File
@@ -0,0 +1,37 @@
# Activity-Relay 2.0.9 (yukimochi): a Mastodon-style relay as relay.test. A server subscribes by following Public from an
# actor with a shared inbox; the relay then passes on, signed with its own key, every public activity another subscriber
# sends it (a LitePub-style follower, whose actor ends in /relay, gets an Announce instead). Its state is in the shared
# Redis (database 13); its actor key is made once. Go trusts the bundle the pasture mounts over the system one.
RELAY_IMAGE=${RELAY_IMAGE:-docker.io/yukimochi/activity-relay:v2.0.9}
. "$here/peers/shared.sh"
relay_up() {
shared_redis_up
local st="$here/.state/relay"
mkdir -p "$st"
[ -s "$st/actor.pem" ] || openssl genrsa -traditional -out "$st/actor.pem" 2048 2>/dev/null
chmod 644 "$st/actor.pem"
cat > "$st/config.yml" <<-EOF
ACTOR_PEM: /var/lib/relay/actor.pem
REDIS_URL: redis://redis:6379/13
RELAY_BIND: 0.0.0.0:8080
RELAY_DOMAIN: relay.test
RELAY_SERVICENAME: Pasture Relay
JOB_CONCURRENCY: 10
RELAY_ICON: https://relay.test/icon.png
RELAY_IMAGE: https://relay.test/image.png
EOF
for role in server worker; do
podman run -d --replace --name pasture-relay-$role --label pasture=1 --network $net \
-v "$st:/var/lib/relay:z,ro" -v "$ca/bundle.pem:/etc/ssl/certs/ca-certificates.crt:z,ro" \
$RELAY_IMAGE relay --config /var/lib/relay/config.yml $role >/dev/null
done
for _ in $(seq 1 60); do
site relay.test -s -o /dev/null -w '%{http_code}' https://relay.test:6443/actor 2>/dev/null | grep -q 200 && break
sleep 1
done
echo "relay: https://relay.test:6443"
}
# relay_subscribers: the hosts subscribed to the relay, from its Redis
relay_subscribers() { podman exec pasture-redis redis-cli -n 13 --raw keys 'relay:subscription:*' | sed 's/relay:subscription://'; }