peers/misskey.sh runs Misskey on the shared Postgres and Redis. Its config is generated with the pasture's private networks allowed and a setup password, it trusts Caddy's CA through NODE_EXTRA_CA_CERTS, and the first account it makes is the scenario's user. A new Misskey federates with nobody, so the setup also turns federation on. scenarios/misskey.sh adds 35 checks, all passing, as listed in docs/INTEROP.md. They cover posts, CW, MFM source, replies, unicode reactions both ways and their withdrawal, likes as reactions, legacy quotes both ways, polls, specified notes, media, deletes, unfollow, block and statistics. MISSKEY_NAME and MISSKEY_IMAGE are there so Sharkey can reuse the peer. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01ELjqpznMFMNrJoJUj6K5p2
50 lines
2.8 KiB
Bash
50 lines
2.8 KiB
Bash
# Shared by run.sh: the network, Caddy (its CA kept in a volume and copied to .ca/root.crt), Mongo and PrivaPub.
|
|
here="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"; repo="$(cd "$here/../.." && pwd)"
|
|
net=privapub-pasture; publish="$here/.publish"; ca="$here/.ca"
|
|
|
|
site() { curl -k --resolve "$1:6443:127.0.0.1" "${@:2}"; }
|
|
|
|
wait_http() { # url tries
|
|
for _ in $(seq 1 "${2:-60}"); do curl -fsk -o /dev/null "$1" && return 0; sleep 2; done
|
|
echo "timed out waiting for $1" >&2; return 1
|
|
}
|
|
|
|
pasture_base_up() {
|
|
local dotnet=${DOTNET:-$(command -v dotnet || echo ~/.dotnet/dotnet)}
|
|
"$dotnet" publish "$repo/PrivaPub/PrivaPub.csproj" -c Release -r linux-x64 --self-contained true -o "$publish" -v quiet
|
|
cp "$here/appsettings.Pasture.json" "$publish/"
|
|
podman network exists $net || podman network create $net >/dev/null
|
|
podman volume exists pasture-caddy-data || podman volume create pasture-caddy-data >/dev/null
|
|
podman run -d --replace --name pasture-mongo --network $net --network-alias mongo docker.io/library/mongo:8 --quiet >/dev/null
|
|
local aliases=""
|
|
for site in privapub gts mastodon akkoma misskey sharkey lemmy; do aliases="$aliases --network-alias $site.test"; done
|
|
# shellcheck disable=SC2086
|
|
podman run -d --replace --name pasture-caddy --network $net $aliases \
|
|
-p 127.0.0.1:6443:443 --sysctl net.ipv4.ip_unprivileged_port_start=0 -v "$here/Caddyfile:/etc/caddy/Caddyfile:Z,ro" \
|
|
-v pasture-caddy-data:/data docker.io/library/caddy:2 >/dev/null
|
|
local extra=()
|
|
for setting in ${PRIVAPUB_ENV:-}; do extra+=(-e "$setting"); done
|
|
podman run -d --replace --name pasture-privapub --network $net -p 127.0.0.1:6971:80 \
|
|
--sysctl net.ipv4.ip_unprivileged_port_start=0 -e ASPNETCORE_ENVIRONMENT=Pasture "${extra[@]}" -w /app -v "$publish:/app:Z,ro" \
|
|
mcr.microsoft.com/dotnet/runtime-deps:10.0 /app/PrivaPub >/dev/null
|
|
wait_http http://127.0.0.1:6971/build.json
|
|
rm -rf "$ca"; mkdir -p "$ca"
|
|
for _ in $(seq 1 60); do
|
|
podman cp pasture-caddy:/data/caddy/pki/authorities/local/root.crt "$ca/root.crt" 2>/dev/null && [ -s "$ca/root.crt" ] && break
|
|
curl -sk -o /dev/null --resolve privapub.test:6443:127.0.0.1 https://privapub.test:6443/build.json || true
|
|
sleep 1
|
|
done
|
|
[ -s "$ca/root.crt" ] || { echo "Caddy's root certificate could not be copied" >&2; return 1; }
|
|
chmod 644 "$ca/root.crt"
|
|
cat /etc/pki/tls/certs/ca-bundle.crt /etc/ssl/certs/ca-certificates.crt 2>/dev/null > "$ca/bundle.pem" || true
|
|
cat "$ca/root.crt" >> "$ca/bundle.pem"
|
|
chmod 644 "$ca/bundle.pem"
|
|
}
|
|
|
|
pasture_down() {
|
|
podman ps -a --format '{{.Names}}' | grep '^pasture-' | xargs -r podman rm -f >/dev/null 2>&1 || true
|
|
podman volume ls --format '{{.Name}}' | grep '^pasture-' | xargs -r podman volume rm -f >/dev/null 2>&1 || true
|
|
podman network rm $net >/dev/null 2>&1 || true
|
|
rm -rf "$here/.state" "$ca"
|
|
}
|