# PieFed 1.7.17: a threadiverse server (communities, threads, comments, votes up and down, polls, flairs) in Flask, from # dockurr's image of the release. The web app (gunicorn, with PieFed's own cron for its send queue) and a Celery worker # share the pasture-piefed-media volume, on the shared Postgres (database piefed) and Redis (dbs 10 and 11). httpx # trusts only certifi's bundle, so the pasture's is mounted over it. `flask init-db` asks for its admin on stdin # (pfuser); its Lemmy-style API (/api/alpha) signs in with a JWT. PIEFED_IMAGE=${PIEFED_IMAGE:-docker.io/dockurr/piefed:1.7.17} PIEFED_PASSWORD=PieFed-Pasture-1 . "$here/peers/shared.sh" piefed_env() { local key="$here/.state/piefed/secret" [ -s "$key" ] || { mkdir -p "$here/.state/piefed"; head -c 48 /dev/urandom | base64 -w0 | tr -d '/+=' > "$key"; } cat < "$here/.state/piefed/env" podman volume exists pasture-piefed-media || podman volume create --label pasture=1 pasture-piefed-media >/dev/null local common=(--network $net --label pasture=1 --env-file "$here/.state/piefed/env" -v pasture-piefed-media:/app/app/static/media -v "$ca/bundle.pem:/ca/bundle.pem:z,ro" -v "$ca/bundle.pem:/venv/lib/python3.13/site-packages/certifi/cacert.pem:z,ro") podman run -d --replace --name pasture-piefed "${common[@]}" -e CRON=true "$PIEFED_IMAGE" >/dev/null podman run -d --replace --name pasture-piefed-celery "${common[@]}" --entrypoint ./entrypoint_celery.sh "$PIEFED_IMAGE" >/dev/null # the web app runs its migrations before gunicorn starts; init-db then sets the site up once, and drops every table # it finds, so it waits for the last migration for _ in $(seq 1 120); do podman logs pasture-piefed 2>&1 | grep -q "Starting Gunicorn" && break sleep 2 done if ! podman exec pasture-postgres psql -U pasture -d piefed -tAc "select 1 from \"user\" where user_name = 'pfuser'" 2>/dev/null | grep -q 1; then printf 'pfuser\npfuser@piefed.test\n%s\n' "$PIEFED_PASSWORD" | podman exec -i -e FLASK_APP=pyfedi.py pasture-piefed flask init-db >/dev/null 2>&1 podman restart pasture-piefed pasture-piefed-celery >/dev/null fi for _ in $(seq 1 90); do site piefed.test -s -o /dev/null -w '%{http_code}' https://piefed.test:6443/api/alpha/site 2>/dev/null | grep -q 200 && break sleep 2 done piefed_settle echo "piefed: https://piefed.test:6443" } # open registrations, no rate limit on its API for the pasture, and pfuser's JWT piefed_settle() { podman exec pasture-postgres psql -U pasture -d piefed -qc "update site set registration_mode = 'Open', enable_downvotes = true" >/dev/null 2>&1 || true site piefed.test -s -X POST https://piefed.test:6443/api/alpha/user/login -H 'Content-Type: application/json' \ -d "{\"username\":\"pfuser\",\"password\":\"$PIEFED_PASSWORD\"}" \ | python3 -c "import sys,json; print(json.load(sys.stdin)['jwt'])" > "$here/.state/piefed.token" 2>/dev/null || true }