# Iceshrimp.NET (2026.1): the strict one. AuthorizedFetch on (every fetch from it is signed, and it answers unsigned # reads 401), full JSON-LD expansion that drops undefined terms, several reactions per user. .NET, so it trusts Caddy's CA # through SSL_CERT_FILE. On the shared Postgres (database iceshrimp); the town makes its users through its own API. ICESHRIMP_IMAGE=${ICESHRIMP_IMAGE:-iceshrimp.dev/iceshrimp/iceshrimp.net:v2026.1.2-beta} . "$here/peers/shared.sh" iceshrimp_up() { shared_postgres_up pg_db iceshrimp mkdir -p "$here/.state/iceshrimp/media" cat > "$here/.state/iceshrimp/configuration.ini" <<'INI' [Instance] ListenPort = 3000 ListenHost = 0.0.0.0 WebDomain = iceshrimp.test AccountDomain = iceshrimp.test CharacterLimit = 8192 [Security] AuthorizedFetch = true ValidateRequestSignatures = true AllowLoopback = true AllowLocalIPv4 = true AllowLocalIPv6 = true Registrations = Open FederationMode = BlockList PublicPreview = Public [Database] Host = postgres Port = 5432 Database = iceshrimp Username = pasture Password = pasture MaxConnections = 50 [Storage] Provider = Local MaxUploadSize = 100M ProxyRemoteMedia = true [Storage:Local] Path = /app/media [Logging:LogLevel] Default = Information Microsoft.AspNetCore = Warning Microsoft.EntityFrameworkCore = Warning INI chmod -R a+rwX "$here/.state/iceshrimp" podman run -d --replace --name pasture-iceshrimp --network $net -e SSL_CERT_FILE=/pasture/ca/bundle.pem \ -v "$here/.state/iceshrimp/configuration.ini:/app/configuration.ini:z,ro" -v "$here/.state/iceshrimp/media:/app/media:z" \ -v "$ca:/pasture/ca:z,ro" $ICESHRIMP_IMAGE >/dev/null for _ in $(seq 1 90); do site iceshrimp.test -s -o /dev/null -w '%{http_code}' https://iceshrimp.test:6443/api/v1/instance 2>/dev/null | grep -q 200 && break sleep 2 done echo "iceshrimp: https://iceshrimp.test:6443" }