Files
archy/apps/podsteadr/push-to-registry.sh
T
ssmithx 395e26b524 feat(apps): package podsteadr as a full Archipelago app (3-container manifest set)
Adds apps/podsteadr (main Fastify+Vue app, container.build from the podsteadr
repo), apps/podsteadr-mediamtx (RTMP/WHIP ingest, HLS, recording), and
apps/podsteadr-blossom (BUD-02 media blobs), wired together on a dedicated
podsteadr-net bridge network per the multi-container pattern documented in
docs/app-developer-guide.md (indeedhub's api/relay/minio/redis/postgres
siblings). All podsteadr ports are auth: none with a rationale, since it's a
public podcast/livestream server whose RSS feeds, HLS playback, and blob
reads must stay reachable by third-party clients with no Archipelago session
— the app already gates its own sensitive routes with NIP-98 and per-stream
secret keys.

Also updates apps/PORTS.md, apps/README.md, and bumps the reviewed
unauthenticated-port count in core/container/src/manifest.rs's
unauthenticated_ports_are_all_accounted_for test (25 -> 31) to acknowledge
the six new auth:none ports. Regenerated catalog-derived files
(core/archipelago/src/fips/app_ports.rs,
neode-ui/src/views/appSession/generatedAppSessionConfig.ts) via
scripts/generate-app-catalog.py.

All three manifests pass scripts/validate-app-manifest.sh and
`cargo test -p archipelago-container manifest`.
2026-08-08 00:18:02 +00:00

58 lines
1.5 KiB
Bash
Executable File

#!/bin/bash
# Build and push the podsteadr container image to a registry.
# Usage: ./push-to-registry.sh [version]
#
# Environment variables:
# REGISTRY - Registry host (default: 146.59.87.168:3000, same as indeedhub/botfights)
# NAMESPACE - Registry namespace (default: lfg2025)
# RUNTIME - Container runtime (default: podman)
set -e
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
REPO_DIR="${PODSTEADR_REPO:-$HOME/podsteadr}"
VERSION="${1:-1.0.0}"
REGISTRY="${REGISTRY:-146.59.87.168:3000}"
NAMESPACE="${NAMESPACE:-lfg2025}"
IMAGE_NAME="podsteadr"
RUNTIME="${RUNTIME:-podman}"
FULL_TAG="${REGISTRY}/${NAMESPACE}/${IMAGE_NAME}:${VERSION}"
if [ ! -d "$REPO_DIR" ]; then
echo "podsteadr repo not found at: $REPO_DIR"
echo "Set PODSTEADR_REPO=/path/to/podsteadr"
exit 1
fi
echo "=== podsteadr Container Registry Push ==="
echo "Source: $REPO_DIR"
echo "Image: $FULL_TAG"
echo "Runtime: $RUNTIME"
echo ""
echo "[1/3] Building image..."
$RUNTIME build --platform linux/amd64 \
-t "$FULL_TAG" \
-t "localhost/${IMAGE_NAME}:${VERSION}" \
-f "$SCRIPT_DIR/Dockerfile" \
"$REPO_DIR"
echo "[2/3] Pushing to registry..."
if ! $RUNTIME login --get-login "$REGISTRY" >/dev/null 2>&1; then
echo ""
echo "Not logged in to $REGISTRY."
echo "Run: $RUNTIME login $REGISTRY"
exit 1
fi
$RUNTIME push "$FULL_TAG"
echo ""
echo "[3/3] Done!"
echo ""
echo "Image pushed: $FULL_TAG"
echo ""
echo "Update apps/podsteadr/manifest.yml's container.image to $FULL_TAG so"
echo "nodes pull it instead of building locally."