# PeerTube 8.3: videos as ActivityPub objects (Video with its files, HLS playlists, captions and storyboards), comments # as Notes, likes and dislikes, accounts and channels as separate actors. On the shared Postgres (database peertube) and # Redis (db 4). Node, so it trusts Caddy's CA through NODE_EXTRA_CA_CERTS; its SSRF guard lets the pasture's public-looking # subnet through. Transcoding is turned off once it is up, so a test video is served as it was uploaded. Its admin is # root, with the password below; the town makes its users through the admin API. PEERTUBE_IMAGE=${PEERTUBE_IMAGE:-docker.io/chocobozzz/peertube:v8.3.1} PEERTUBE_ROOT_PASSWORD=Peertube-Pasture-Root-1 . "$here/peers/shared.sh" peertube_up() { shared_postgres_up shared_redis_up pg_db peertube pg_trgm unaccent mkdir -p "$here/.state/peertube/data" "$here/.state/peertube/config" podman run -d --replace --name pasture-peertube --network $net \ -e PEERTUBE_WEBSERVER_HOSTNAME=peertube.test -e PEERTUBE_WEBSERVER_PORT=443 -e PEERTUBE_WEBSERVER_HTTPS=true \ -e PEERTUBE_TRUST_PROXY='["loopback", "linklocal", "uniquelocal", "'"$subnet"'"]' \ -e PEERTUBE_DB_HOSTNAME=postgres -e PEERTUBE_DB_NAME=peertube -e PEERTUBE_DB_SUFFIX= \ -e PEERTUBE_DB_USERNAME=pasture -e PEERTUBE_DB_PASSWORD=pasture \ -e PEERTUBE_REDIS_HOSTNAME=redis -e PEERTUBE_REDIS_DB=4 \ -e PEERTUBE_SECRET=pasture-peertube-secret-0123456789abcdef -e PEERTUBE_ADMIN_EMAIL=admin@peertube.test \ -e PT_INITIAL_ROOT_PASSWORD=$PEERTUBE_ROOT_PASSWORD \ -e PEERTUBE_RATES_LIMIT_API_MAX=100000 -e PEERTUBE_RATES_LIMIT_LOGIN_MAX=100000 -e PEERTUBE_RATES_LIMIT_ACTIVITY_PUB_MAX=100000 \ -e PEERTUBE_SIGNUP_ENABLED=true \ -e NODE_EXTRA_CA_CERTS=/pasture/ca/root.crt \ -v "$here/.state/peertube/data:/data:Z" -v "$here/.state/peertube/config:/config:Z" -v "$ca:/pasture/ca:z,ro" \ "$PEERTUBE_IMAGE" >/dev/null for _ in $(seq 1 150); do site peertube.test -s -o /dev/null -w '%{http_code}' https://peertube.test:6443/api/v1/config 2>/dev/null | grep -q 200 && break sleep 3 done peertube_settle echo "peertube: https://peertube.test:6443" } # root's token (the password grant with the instance's own client); transcoding off, signups open, any import allowed peertube_settle() { local client token # PeerTube gives its client only to its own host, named without the port client=$(site peertube.test -s -H "Host: peertube.test" https://peertube.test:6443/api/v1/oauth-clients/local) token=$(site peertube.test -s -X POST https://peertube.test:6443/api/v1/users/token \ --data-urlencode "client_id=$(echo "$client" | python3 -c 'import sys,json; print(json.load(sys.stdin)["client_id"])')" \ --data-urlencode "client_secret=$(echo "$client" | python3 -c 'import sys,json; print(json.load(sys.stdin)["client_secret"])')" \ --data-urlencode grant_type=password --data-urlencode username=root --data-urlencode "password=$PEERTUBE_ROOT_PASSWORD" \ | python3 -c 'import sys,json; print(json.load(sys.stdin)["access_token"])') echo "$token" > "$here/.state/peertube.token" site peertube.test -s https://peertube.test:6443/api/v1/config/custom -H "Authorization: Bearer $token" | python3 -c ' import sys, json c = json.load(sys.stdin) c["transcoding"]["enabled"] = False c["signup"]["enabled"] = True c["signup"]["requiresEmailVerification"] = False c["signup"]["limit"] = -1 c["user"]["videoQuota"] = -1 c["user"]["videoQuotaDaily"] = -1 print(json.dumps(c))' > "$here/.state/peertube/custom.json" site peertube.test -s -o /dev/null -w '%{http_code}\n' -X PUT https://peertube.test:6443/api/v1/config/custom -H "Authorization: Bearer $token" \ -H 'Content-Type: application/json' --data @"$here/.state/peertube/custom.json" }