Pleroma 2.10.2 runs in the pasture from its OTP release (libvips, the dedupe question, and hackney pointed at the system CA bundle); its driver is Akkoma's on its own container and database. The pair passes 241 cells, after its first run showed Pleroma dropping Follows it could not verify yet. The PrivaPub driver finds the group an earlier run made instead of failing on the name; the seeder posts a quote or reply of a post from its own round after that post. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
28 lines
1.7 KiB
Bash
Executable File
28 lines
1.7 KiB
Bash
Executable File
#!/bin/sh
|
|
# Trusts the pasture's CA, writes the config on first start, migrates, and runs Pleroma in the foreground.
|
|
set -e
|
|
cp /pasture/ca/root.crt /usr/local/share/ca-certificates/pasture.crt && update-ca-certificates >/dev/null
|
|
# Mint and Gun read the bundles shipped in the release (CAStore, certifi), never the system's
|
|
for bundle in /opt/pleroma/lib/castore-*/priv/cacerts.pem /opt/pleroma/lib/certifi-*/priv/cacerts.pem; do
|
|
[ -f "$bundle" ] || continue
|
|
grep -q "pasture" "$bundle" || { echo "# pasture"; cat /pasture/ca/root.crt; } >> "$bundle"
|
|
done
|
|
if [ ! -f /etc/pleroma/config.exs ]; then
|
|
# pleroma_ctl passes its arguments on unquoted, so no value may contain a space
|
|
env -u PLEROMA_CONFIG_PATH /opt/pleroma/bin/pleroma_ctl instance gen --force --output /etc/pleroma/config.exs --output-psql /tmp/setup.psql \
|
|
--domain pleroma.test --instance-name PasturePleroma --admin-email admin@pleroma.test --notify-email admin@pleroma.test \
|
|
--dbhost postgres --dbname pleroma --dbuser pasture --dbpass pasture --rum N --indexable N --db-configurable N \
|
|
--uploads-dir /var/lib/pleroma/uploads --static-dir /var/lib/pleroma/static --listen-ip 0.0.0.0 --listen-port 4000 \
|
|
--strip-uploads-location N --read-uploads-description Y --anonymize-uploads N --dedupe-uploads N \
|
|
</dev/null
|
|
fi
|
|
# Pleroma federates through hackney, which trusts certifi's compiled-in roots and never a file: name the system bundle,
|
|
# which holds Caddy's root since update-ca-certificates
|
|
grep -q "pasture: system CA bundle" /etc/pleroma/config.exs || cat >> /etc/pleroma/config.exs <<'EOF'
|
|
|
|
# pasture: system CA bundle
|
|
config :pleroma, :http, adapter: [ssl_options: [cacertfile: "/etc/ssl/certs/ca-certificates.crt"]]
|
|
EOF
|
|
/opt/pleroma/bin/pleroma_ctl migrate
|
|
exec /opt/pleroma/bin/pleroma start
|