feat!: remove rathole package - superseded by netbird [#650]
Founder ruling: "we will use netbird for all enterprise network
access." Package dir deleted (11th package, f918a90, is hereby
retired); GitUrlList 41->40; counts 19->18; completed tables
renumbered; JOURNAL section retained as history with a superseding
addendum. Standing policy recorded: netbird for network access.
This commit is contained in:
@@ -15,7 +15,6 @@ https://github.com/healthchecks/healthchecks
|
|||||||
https://github.com/fleetdm/fleet
|
https://github.com/fleetdm/fleet
|
||||||
https://github.com/netbox-community/netbox
|
https://github.com/netbox-community/netbox
|
||||||
https://github.com/apache/seatunnel
|
https://github.com/apache/seatunnel
|
||||||
https://github.com/rapiz1/rathole
|
|
||||||
https://github.com/wiredlush/easy-gate
|
https://github.com/wiredlush/easy-gate
|
||||||
https://github.com/consuldemocracy/consuldemocracy
|
https://github.com/consuldemocracy/consuldemocracy
|
||||||
https://github.com/BOINC/boinc
|
https://github.com/BOINC/boinc
|
||||||
|
|||||||
@@ -893,6 +893,14 @@ traversal (frp/ngrok class, Rust); this package runs the **server** side
|
|||||||
|
|
||||||
**Commit**: `feat: add Rathole Cloudron package (Infrastructure) [#650]`
|
**Commit**: `feat: add Rathole Cloudron package (Infrastructure) [#650]`
|
||||||
|
|
||||||
|
> **SUPERSEDED / REMOVED 2026-09-06** by founder ruling on
|
||||||
|
> [#650](https://projects.knownelement.com/issues/650): *"remove this.
|
||||||
|
> we will use netbird for all enterprise network access."* The package
|
||||||
|
> directory was deleted and the app dropped from GitUrlList and all
|
||||||
|
> counts. This section is retained (append-only) as the historical
|
||||||
|
> record of the pre-compiled-binaries pattern work.
|
||||||
|
|
||||||
|
|
||||||
### 12. Database Gateway (Infrastructure) ✅
|
### 12. Database Gateway (Infrastructure) ✅
|
||||||
**Date**: 2026-09-01
|
**Date**: 2026-09-01
|
||||||
**Application**: Database Gateway (dbgw) — policy-checked web gateway to
|
**Application**: Database Gateway (dbgw) — policy-checked web gateway to
|
||||||
|
|||||||
@@ -1 +0,0 @@
|
|||||||
repo
|
|
||||||
@@ -1,8 +0,0 @@
|
|||||||
# Rathole Cloudron package — environment knobs
|
|
||||||
#
|
|
||||||
# Cloudron injects these at runtime (App -> Configure -> Environment);
|
|
||||||
# they are not secrets.
|
|
||||||
|
|
||||||
# Log level for the rathole server: error | warn | info | debug | trace.
|
|
||||||
# Default when unset: info
|
|
||||||
RUST_LOG=info
|
|
||||||
@@ -1,27 +0,0 @@
|
|||||||
# Changelog — Rathole Cloudron Package
|
|
||||||
|
|
||||||
## 1.0.0 (2026-09-01)
|
|
||||||
|
|
||||||
Initial Cloudron package for Rathole 0.5.0 (server mode).
|
|
||||||
|
|
||||||
- Pre-compiled-binaries pattern: upstream `x86_64-unknown-linux-gnu`
|
|
||||||
release zip downloaded at build time behind a sha256 pin (musl release
|
|
||||||
builds were dropped upstream in v0.5.0).
|
|
||||||
- Runtime `cloudron/base:4.0.0` (Ubuntu 22.04): the gnu binary requires
|
|
||||||
glibc >= 2.35, too new for the 3.x (20.04) base used by earlier
|
|
||||||
packages.
|
|
||||||
- `start.sh` seeds `/app/data/server.toml` on first run with a random
|
|
||||||
`default_token` (openssl) and a placeholder `[server.services.example]`
|
|
||||||
binding :5200 — upstream rejects a server config with zero services —
|
|
||||||
then execs `rathole --server`; the config hot-reloads on save.
|
|
||||||
- Verified end-to-end at build time: a client container tunneled its own
|
|
||||||
HTTP server through the packaged server (token auth, lazy service bind,
|
|
||||||
hot-reload of added services).
|
|
||||||
- TCP surface: control channel on 2333 + a 100-port tunnel exit range
|
|
||||||
(5200-5299) declared via `tcpPorts` with `containerPort`/`portCount`.
|
|
||||||
- No user concept → `httpAuth.type = proxy` gates a small static status
|
|
||||||
page served on the HTTP port (also serves as the platform health
|
|
||||||
check); tunnel access itself is controlled by rathole's mandatory
|
|
||||||
per-service tokens.
|
|
||||||
- Addons: `localstorage` only (config persistence; no database).
|
|
||||||
- Logo padded from the upstream wordmark to a 256x256 PNG.
|
|
||||||
@@ -1,43 +0,0 @@
|
|||||||
{
|
|
||||||
"manifestVersion": 2,
|
|
||||||
"type": "app",
|
|
||||||
"id": "io.cloudron.rathole",
|
|
||||||
"title": "Rathole",
|
|
||||||
"description": "Rathole is a secure, stable and high-performance reverse proxy for NAT traversal, written in Rust. This package runs the server side: clients behind NAT connect to the control port with per-service token authentication (optionally Noise/TLS encrypted) and expose their local services through tunnels on the reserved port range. Configuration lives in /app/data/server.toml and hot-reloads on save. No database required.",
|
|
||||||
"author": "rapiz1 / rathole-org",
|
|
||||||
"website": "https://github.com/rathole-org/rathole",
|
|
||||||
"documentationUrl": "https://github.com/rathole-org/rathole/blob/main/README.md",
|
|
||||||
"contactEmail": "cloudron@tsys.dev",
|
|
||||||
"tagline": "Secure, high-performance reverse-tunnel server for NAT traversal",
|
|
||||||
"version": "0.5.0",
|
|
||||||
"upstreamVersion": "0.5.0",
|
|
||||||
"healthCheckPath": "/",
|
|
||||||
"httpPort": 8000,
|
|
||||||
"httpAuth": {
|
|
||||||
"type": "proxy"
|
|
||||||
},
|
|
||||||
"tcpPorts": {
|
|
||||||
"CONTROL_PORT": {
|
|
||||||
"title": "Control channel port",
|
|
||||||
"description": "TCP port that rathole clients connect to in order to establish tunnels. Change only if it collides with another exposed app on this Cloudron.",
|
|
||||||
"defaultValue": 2333,
|
|
||||||
"containerPort": 2333,
|
|
||||||
"portCount": 1
|
|
||||||
},
|
|
||||||
"SERVICE_PORT": {
|
|
||||||
"title": "Tunnel exit ports",
|
|
||||||
"description": "Start of the sequential port range reserved for tunneled services (100 ports by default: 5200-5299). Each [server.services.*] block in /app/data/server.toml binds one port from this range; the config hot-reloads, so services can be added without a restart.",
|
|
||||||
"defaultValue": 5200,
|
|
||||||
"containerPort": 5200,
|
|
||||||
"portCount": 100
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"memoryLimit": 268435456,
|
|
||||||
"addons": {
|
|
||||||
"localstorage": {}
|
|
||||||
},
|
|
||||||
"postInstallMessage": "Rathole is headless: there is nothing to click through. Open the **file manager** and edit **/app/data/server.toml** to define tunnel services (a random default token was generated on first start). The config hot-reloads on save. The client-side setup is documented in the package README.",
|
|
||||||
"mediaLinks": [],
|
|
||||||
"changelog": "Initial Cloudron package for Rathole 0.5.0 (server mode). Pre-compiled upstream binary with sha256 pin, token-authenticated tunnels on control port 2333 plus a 100-port service range (5200-5299), config with hot reload at /app/data/server.toml, and an auth-proxied status page on the HTTP port.",
|
|
||||||
"icon": "file://logo.png"
|
|
||||||
}
|
|
||||||
@@ -1,48 +0,0 @@
|
|||||||
# Rathole Cloudron Package
|
|
||||||
#
|
|
||||||
# Rathole is a secure, stable and high-performance reverse proxy for NAT
|
|
||||||
# traversal (frp/ngrok class, written in Rust). This package runs the
|
|
||||||
# SERVER side: the Cloudron box is the public-IP endpoint, rathole clients
|
|
||||||
# behind NAT dial the control port (2333) and expose their local services
|
|
||||||
# through token-authenticated tunnels on the 5200+ port range.
|
|
||||||
#
|
|
||||||
# Upstream: https://github.com/rathole-org/rathole (v0.5.0)
|
|
||||||
# - Ships a prebuilt x86_64-unknown-linux-gnu release binary (musl
|
|
||||||
# release builds were dropped upstream in v0.5.0)
|
|
||||||
# - No database, no user accounts; per-service tokens are mandatory
|
|
||||||
#
|
|
||||||
# Authentication: Rathole has NO user concept (tunnels are authorized by
|
|
||||||
# per-service tokens, optionally Noise/TLS encrypted at the transport
|
|
||||||
# layer). The status page on the HTTP port is gated by Cloudron's
|
|
||||||
# authentication proxy (httpAuth.type = proxy).
|
|
||||||
#
|
|
||||||
# Base image: cloudron/base:4.0.0 (Ubuntu 22.04). The upstream gnu binary
|
|
||||||
# is built on ubuntu-latest, so the runtime needs glibc >= 2.35 —
|
|
||||||
# cloudron/base:3.2.0 (20.04) is too old for it.
|
|
||||||
FROM cloudron/base:4.0.0
|
|
||||||
|
|
||||||
ARG RATHOLE_VERSION=0.5.0
|
|
||||||
ARG RATHOLE_SHA256=3e7d0d0f365120cd3cd351d147d1a12ee960c8068b464d4dd533a3821873b80e
|
|
||||||
|
|
||||||
# Pre-compiled-binaries pattern (see JOURNAL.md): download the pinned
|
|
||||||
# upstream release, verify the sha256 gate, install the binary.
|
|
||||||
RUN curl -fsSL -o /tmp/rathole.zip \
|
|
||||||
"https://github.com/rathole-org/rathole/releases/download/v${RATHOLE_VERSION}/rathole-x86_64-unknown-linux-gnu.zip" \
|
|
||||||
&& echo "${RATHOLE_SHA256} /tmp/rathole.zip" | sha256sum -c - \
|
|
||||||
&& unzip -o /tmp/rathole.zip -d /usr/local/bin \
|
|
||||||
&& chmod +x /usr/local/bin/rathole \
|
|
||||||
&& rm -f /tmp/rathole.zip \
|
|
||||||
&& /usr/local/bin/rathole --version
|
|
||||||
|
|
||||||
# Static status page served on the Cloudron HTTP port (platform health
|
|
||||||
# check + auth-proxied landing page). start.sh seeds /app/data/server.toml
|
|
||||||
# on first run and execs rathole in server mode. start.sh is made
|
|
||||||
# executable on the host, not at build time (Cloudron gotcha).
|
|
||||||
COPY status.html /app/code/status/index.html
|
|
||||||
COPY start.sh /app/start.sh
|
|
||||||
|
|
||||||
WORKDIR /app/data
|
|
||||||
|
|
||||||
EXPOSE 8000 2333 5200-5299
|
|
||||||
|
|
||||||
CMD ["/bin/bash", "/app/start.sh"]
|
|
||||||
@@ -1,95 +0,0 @@
|
|||||||
# Rathole — Cloudron Package
|
|
||||||
|
|
||||||
[Rathole](https://github.com/rathole-org/rathole) is a secure, stable and
|
|
||||||
high-performance reverse proxy for NAT traversal (frp/ngrok class, written
|
|
||||||
in Rust). This package runs the **server** side: the Cloudron box is the
|
|
||||||
public-IP endpoint, rathole clients behind NAT dial the control port, and
|
|
||||||
their local services are exposed through token-authenticated tunnels.
|
|
||||||
|
|
||||||
## Packaging overview
|
|
||||||
|
|
||||||
| Aspect | Choice |
|
|
||||||
|--------|--------|
|
|
||||||
| Pattern | Pre-compiled binaries (JOURNAL pattern #5) |
|
|
||||||
| Base image | `cloudron/base:4.0.0` (Ubuntu 22.04) |
|
|
||||||
| Upstream binary | `rathole-x86_64-unknown-linux-gnu.zip`, v0.5.0, sha256-pinned in Dockerfile |
|
|
||||||
| Addons | `localstorage` only (config persistence; no database) |
|
|
||||||
| Auth | No user concept → `httpAuth.type = proxy` (see below) |
|
|
||||||
| Runtime | `start.sh` seeds config, serves status page, execs rathole `--server` |
|
|
||||||
|
|
||||||
Why pre-compiled: upstream ships release binaries and **dropped the musl
|
|
||||||
builds in v0.5.0** (only `x86_64-unknown-linux-gnu` remains for Linux
|
|
||||||
amd64). The gnu binary is built on ubuntu-latest, so the runtime needs
|
|
||||||
glibc >= 2.35 — hence `cloudron/base:4.0.0` (22.04) instead of the 3.x
|
|
||||||
series (20.04). Compiling from source would need a full Rust toolchain
|
|
||||||
build stage for no benefit.
|
|
||||||
|
|
||||||
## Authentication (auth gate verdict: proxy)
|
|
||||||
|
|
||||||
- Rathole has **no user concept**: no web UI, no accounts, no SSO hooks.
|
|
||||||
- Tunnels are authorized by **mandatory per-service tokens** (a random
|
|
||||||
`default_token` is generated into `/app/data/server.toml` on first
|
|
||||||
start). Transport can additionally be encrypted via Noise or TLS.
|
|
||||||
- The manifest declares `httpAuth: {"type": "proxy"}`: Cloudron's auth
|
|
||||||
proxy gates the HTTP status page, which is the only HTTP surface this
|
|
||||||
app has. The raw TCP tunnel ports cannot be HTTP-gated by design; the
|
|
||||||
token layer is their access control.
|
|
||||||
|
|
||||||
## Ports
|
|
||||||
|
|
||||||
| Port | Type | Purpose |
|
|
||||||
|------|------|---------|
|
|
||||||
| 8000 | `httpPort` | Status/health page (behind Cloudron auth proxy) |
|
|
||||||
| 2333 | `tcpPorts` | Control channel — rathole clients connect here |
|
|
||||||
| 5200–5299 | `tcpPorts` (100-port range) | Tunnel exit ports — one per `[server.services.*]` |
|
|
||||||
|
|
||||||
With default install settings Cloudron bridges these 1:1 (external
|
|
||||||
5200-5299 → container 5200-5299). If the admin picks a different
|
|
||||||
`SERVICE_PORT` start value, the *container* ports stay 5200+ and only the
|
|
||||||
external numbering shifts — `server.toml` never needs editing for that.
|
|
||||||
|
|
||||||
## Configuration
|
|
||||||
|
|
||||||
`/app/data/server.toml`, seeded on first run, **hot-reloaded on save**
|
|
||||||
(add/remove services without restarting the app). The seed contains a
|
|
||||||
placeholder `[server.services.example]` on :5200 — rathole rejects a
|
|
||||||
server config with zero services, so keep at least one block. Example
|
|
||||||
service:
|
|
||||||
|
|
||||||
```toml
|
|
||||||
[server.services.my_nas_ssh]
|
|
||||||
token = "<copy from default_token or set your own>"
|
|
||||||
bind_addr = "0.0.0.0:5200"
|
|
||||||
```
|
|
||||||
|
|
||||||
Client side (machine behind NAT):
|
|
||||||
|
|
||||||
```toml
|
|
||||||
[client]
|
|
||||||
remote_addr = "your-cloudron.example.com:2333"
|
|
||||||
|
|
||||||
[client.services.my_nas_ssh]
|
|
||||||
token = "<same token as the server>"
|
|
||||||
local_addr = "127.0.0.1:22"
|
|
||||||
```
|
|
||||||
|
|
||||||
Then `ssh -p 5200 user@your-cloudron.example.com` reaches the NAS.
|
|
||||||
|
|
||||||
Knob: `RUST_LOG` (error|warn|info|debug|trace, default `info`) via
|
|
||||||
Cloudron environment settings — see `.env.example`.
|
|
||||||
|
|
||||||
## Build & test
|
|
||||||
|
|
||||||
```bash
|
|
||||||
docker build --cgroup-parent ukrrs-batch.slice -t rathole-cloudron:test Package-Workspace/Infrastructure/rathole/
|
|
||||||
docker run --rm --entrypoint /usr/local/bin/rathole rathole-cloudron:test --version
|
|
||||||
```
|
|
||||||
|
|
||||||
## Files
|
|
||||||
|
|
||||||
- `Dockerfile` — pinned release download + sha256 gate on cloudron/base:4.0.0
|
|
||||||
- `CloudronManifest.json` — manifestVersion 2, httpAuth proxy, tcpPorts (control + 100-port service range)
|
|
||||||
- `start.sh` — config seeding, status page, exec rathole server mode
|
|
||||||
- `status.html` — auth-proxied landing/health page
|
|
||||||
- `.env.example` — runtime knobs
|
|
||||||
- `logo.png` — 256x256, padded from upstream wordmark
|
|
||||||
Binary file not shown.
|
Before Width: | Height: | Size: 11 KiB |
@@ -1,54 +0,0 @@
|
|||||||
#!/bin/bash
|
|
||||||
set -euo pipefail
|
|
||||||
|
|
||||||
# Rathole runs in SERVER mode on Cloudron: the box has the public IP and
|
|
||||||
# rathole clients behind NAT dial in on the control port (container port
|
|
||||||
# 2333, bridged 1:1 by default). Tunneled services bind container ports
|
|
||||||
# 5200-5299, which Cloudron exposes in sequence from the SERVICE_PORT
|
|
||||||
# value chosen at install time.
|
|
||||||
#
|
|
||||||
# Rathole has no HTTP interface of its own, so a tiny static status page
|
|
||||||
# is served on the Cloudron HTTP port. That gives the platform a health
|
|
||||||
# check endpoint and gives the admin an auth-proxied landing page
|
|
||||||
# (httpAuth.type = proxy gates it at the platform edge).
|
|
||||||
|
|
||||||
export RATHOLE_CONFIG="/app/data/server.toml"
|
|
||||||
|
|
||||||
if [[ ! -f "${RATHOLE_CONFIG}" ]]; then
|
|
||||||
default_token="$(openssl rand -hex 24)"
|
|
||||||
cat > "${RATHOLE_CONFIG}" <<EOF
|
|
||||||
# rathole server configuration — hot-reloaded on save, no restart needed.
|
|
||||||
# Full reference: https://github.com/rathole-org/rathole#configuration
|
|
||||||
|
|
||||||
[server]
|
|
||||||
bind_addr = "0.0.0.0:2333"
|
|
||||||
default_token = "${default_token}"
|
|
||||||
heartbeat_interval = 30
|
|
||||||
|
|
||||||
[server.transport]
|
|
||||||
type = "tcp"
|
|
||||||
|
|
||||||
[server.transport.tcp]
|
|
||||||
nodelay = true
|
|
||||||
|
|
||||||
# At least one service block must exist — rathole rejects a server config
|
|
||||||
# with no services. This placeholder listens on the first tunnel port and
|
|
||||||
# forwards whatever the matching client sends. Rename it or add more
|
|
||||||
# blocks; each bind_addr must use a distinct port from the reserved range
|
|
||||||
# (5200-5299 with default install settings). Hot-reloads on save.
|
|
||||||
[server.services.example]
|
|
||||||
token = "${default_token}"
|
|
||||||
bind_addr = "0.0.0.0:5200"
|
|
||||||
|
|
||||||
#[server.services.my_web_app]
|
|
||||||
#token = "another_secret"
|
|
||||||
#bind_addr = "0.0.0.0:5201"
|
|
||||||
EOF
|
|
||||||
echo "Seeded default config at ${RATHOLE_CONFIG} (random default_token generated)"
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Status page (health check + auth-proxied landing page) in the background;
|
|
||||||
# rathole stays in the foreground as PID-friendly main process.
|
|
||||||
python3 -m http.server "${CLOUDRON_HTTP_PORT:-8000}" --directory /app/code/status &
|
|
||||||
|
|
||||||
exec /usr/local/bin/rathole --server "${RATHOLE_CONFIG}"
|
|
||||||
@@ -1,51 +0,0 @@
|
|||||||
<!DOCTYPE html>
|
|
||||||
<html lang="en">
|
|
||||||
<head>
|
|
||||||
<meta charset="utf-8">
|
|
||||||
<meta name="viewport" content="width=device-width, initial-scale=1">
|
|
||||||
<title>Rathole (server)</title>
|
|
||||||
<style>
|
|
||||||
body { font-family: -apple-system, "Segoe UI", Roboto, sans-serif; background: #14171c; color: #d8dee6; margin: 0; display: flex; min-height: 100vh; align-items: center; justify-content: center; }
|
|
||||||
main { max-width: 640px; padding: 2rem; }
|
|
||||||
h1 { color: #ffffff; font-size: 1.6rem; margin-bottom: 0.25rem; }
|
|
||||||
p.tagline { color: #7f8c9b; margin-top: 0; }
|
|
||||||
code { background: #1f242c; border: 1px solid #2d3440; border-radius: 4px; padding: 0.1rem 0.35rem; font-size: 0.85rem; color: #9ecbff; }
|
|
||||||
table { border-collapse: collapse; width: 100%; margin: 1rem 0; font-size: 0.9rem; }
|
|
||||||
th, td { text-align: left; padding: 0.5rem 0.75rem; border-bottom: 1px solid #2d3440; }
|
|
||||||
th { color: #7f8c9b; font-weight: 600; }
|
|
||||||
pre { background: #1f242c; border: 1px solid #2d3440; border-radius: 6px; padding: 1rem; overflow-x: auto; font-size: 0.8rem; line-height: 1.5; }
|
|
||||||
.ok { color: #6bc46d; }
|
|
||||||
</style>
|
|
||||||
</head>
|
|
||||||
<body>
|
|
||||||
<main>
|
|
||||||
<h1>Rathole <span class="ok">▲ server running</span></h1>
|
|
||||||
<p class="tagline">Secure, high-performance reverse-tunnel server for NAT traversal</p>
|
|
||||||
|
|
||||||
<p>Rathole is headless — this page exists so Cloudron has a health
|
|
||||||
endpoint and you have a landing spot. Configuration is file-based and
|
|
||||||
<strong>hot-reloads on save</strong>: edit
|
|
||||||
<code>/app/data/server.toml</code> with the Cloudron file manager to add
|
|
||||||
or remove tunnel services. A random <code>default_token</code> was
|
|
||||||
generated on first start; copy it from that file.</p>
|
|
||||||
|
|
||||||
<table>
|
|
||||||
<tr><th>Port</th><th>Purpose</th></tr>
|
|
||||||
<tr><td>2333</td><td>Control channel — rathole clients connect here</td></tr>
|
|
||||||
<tr><td>5200–5299</td><td>Tunnel exit ports — one per <code>[server.services.*]</code> block</td></tr>
|
|
||||||
<tr><td>HTTP (this page)</td><td>Status/health only, gated by the Cloudron auth proxy</td></tr>
|
|
||||||
</table>
|
|
||||||
|
|
||||||
<p>Client side (on the machine behind NAT), with a matching service block on the server:</p>
|
|
||||||
<pre>[client]
|
|
||||||
remote_addr = "your-cloudron.example.com:2333"
|
|
||||||
|
|
||||||
[client.services.my_nas_ssh]
|
|
||||||
token = "<same token as the server>"
|
|
||||||
local_addr = "127.0.0.1:22"</pre>
|
|
||||||
|
|
||||||
<p style="color:#7f8c9b;font-size:0.85rem;">Upstream docs:
|
|
||||||
<a style="color:#9ecbff" href="https://github.com/rathole-org/rathole">github.com/rathole-org/rathole</a></p>
|
|
||||||
</main>
|
|
||||||
</body>
|
|
||||||
</html>
|
|
||||||
@@ -9,9 +9,9 @@ The Cloudron component focuses on packaging upstream free/libre/open application
|
|||||||
### 📊 Current Progress
|
### 📊 Current Progress
|
||||||
|
|
||||||
- **Total Applications**: 41 (see [GitUrlList.txt](GitUrlList.txt); pruned 2026-09-06 by rulings: no-Node, no-open-core, no-SSO-tax, k8s redirects, out-of-scope)
|
- **Total Applications**: 41 (see [GitUrlList.txt](GitUrlList.txt); pruned 2026-09-06 by rulings: no-Node, no-open-core, no-SSO-tax, k8s redirects, out-of-scope)
|
||||||
- **Completed Packages**: 19/41 (~46% of the post-ruling set)
|
- **Completed Packages**: 18/40 (~45% of the post-ruling set)
|
||||||
- **Packaging Templates**: Created ✅
|
- **Packaging Templates**: Created ✅
|
||||||
- **Packages Committed & Pushed**: 19 ✅
|
- **Packages Committed & Pushed**: 18 ✅ (rathole removed by ruling)
|
||||||
- **Build Tickets**: rulings synced 2026-09-06 (#633-#678 batch, umbrella
|
- **Build Tickets**: rulings synced 2026-09-06 (#633-#678 batch, umbrella
|
||||||
[#632](https://projects.knownelement.com/issues/632), Redmine project 55);
|
[#632](https://projects.knownelement.com/issues/632), Redmine project 55);
|
||||||
grist-core excluded (packaged upstream)
|
grist-core excluded (packaged upstream)
|
||||||
@@ -32,15 +32,14 @@ The Cloudron component focuses on packaging upstream free/libre/open application
|
|||||||
| 8 | draw.io | Documentation-Tools | — | 8080 | none (auth proxy) | ✅ Committed |
|
| 8 | draw.io | Documentation-Tools | — | 8080 | none (auth proxy) | ✅ Committed |
|
||||||
| 9 | Windmill | Automation | ~2GB | 8000 | localstorage, postgresql | ✅ Committed |
|
| 9 | Windmill | Automation | ~2GB | 8000 | localstorage, postgresql | ✅ Committed |
|
||||||
| 10 | Easy-Gate | Infrastructure | 3.18GB | 8080 | localstorage (auth proxy) | ✅ Committed |
|
| 10 | Easy-Gate | Infrastructure | 3.18GB | 8080 | localstorage (auth proxy) | ✅ Committed |
|
||||||
| 11 | Rathole | Infrastructure | 3.51GB | 8000, 2333, 5200-5299 | localstorage (auth proxy) | ✅ Committed |
|
| 11 | Database Gateway | Infrastructure | 93.7MB | 8080 | localstorage, postgresql | ✅ Committed |
|
||||||
| 12 | Database Gateway | Infrastructure | 93.7MB | 8080 | localstorage, postgresql | ✅ Committed |
|
| 12 | FX | DevOps-Tools | 3.55GB | 8000 | localstorage (auth proxy) | ✅ Committed |
|
||||||
| 13 | FX | DevOps-Tools | 3.55GB | 8000 | localstorage (auth proxy) | ✅ Committed |
|
| 13 | ChirpStack | Infrastructure | 83.4MB | 8080 | localstorage, postgresql, redis | ✅ Committed |
|
||||||
| 14 | ChirpStack | Infrastructure | 83.4MB | 8080 | localstorage, postgresql, redis | ✅ Committed |
|
| 14 | eLabFTW | Business-Apps | ~209MB (compressed) | 443 | localstorage, mysql, ldap | ✅ Committed |
|
||||||
| 15 | eLabFTW | Business-Apps | ~209MB (compressed) | 443 | localstorage, mysql, ldap | ✅ Committed |
|
| 15 | NetBox | Infrastructure | ~1GB | 8080 | localstorage, postgresql, redis | ✅ Committed |
|
||||||
| 16 | NetBox | Infrastructure | ~1GB | 8080 | localstorage, postgresql, redis | ✅ Committed |
|
| 16 | ConsulDemocracy | Collaboration | ~1.6GB | 3000 | localstorage, postgresql | ✅ Committed |
|
||||||
| 17 | ConsulDemocracy | Collaboration | ~1.6GB | 3000 | localstorage, postgresql | ✅ Committed |
|
| 17 | GoAlert | Monitoring | ~40MB | 8081 | localstorage, postgresql | ✅ Committed |
|
||||||
| 18 | GoAlert | Monitoring | ~40MB | 8081 | localstorage, postgresql | ✅ Committed |
|
| 18 | InvenTree | Business-Apps | ~1.4GB | 8000 | localstorage, postgresql, redis | ✅ Committed |
|
||||||
| 19 | InvenTree | Business-Apps | ~1.4GB | 8000 | localstorage, postgresql, redis | ✅ Committed |
|
|
||||||
|
|
||||||
### 📦 Packages in Development
|
### 📦 Packages in Development
|
||||||
|
|
||||||
@@ -132,7 +131,6 @@ Applications are organized by function rather than programming language:
|
|||||||
| [Fleet](https://github.com/fleetdm/fleet) | [GitHub](https://github.com/fleetdm/fleet) | Device management and monitoring | Monitoring |
|
| [Fleet](https://github.com/fleetdm/fleet) | [GitHub](https://github.com/fleetdm/fleet) | Device management and monitoring | Monitoring |
|
||||||
| [NetBox](https://github.com/netbox-community/netbox) | [GitHub](https://github.com/netbox-community/netbox) | IP address management (IPAM) and data center infrastructure management | Infrastructure | ✅ Packaged
|
| [NetBox](https://github.com/netbox-community/netbox) | [GitHub](https://github.com/netbox-community/netbox) | IP address management (IPAM) and data center infrastructure management | Infrastructure | ✅ Packaged
|
||||||
| [SeaTunnel](https://github.com/apache/seatunnel) | [GitHub](https://github.com/apache/seatunnel) | Data integration and streaming platform | Data-Management |
|
| [SeaTunnel](https://github.com/apache/seatunnel) | [GitHub](https://github.com/apache/seatunnel) | Data integration and streaming platform | Data-Management |
|
||||||
| [Rathole](https://github.com/rapiz1/rathole) | [GitHub](https://github.com/rapiz1/rathole) | Lightweight and high-performance reverse proxy | Infrastructure | ✅ Packaged |
|
|
||||||
| [Easy-Gate](https://github.com/wiredlush/easy-gate) | [GitHub](https://github.com/wiredlush/easy-gate) | Gateway and proxy solution | Infrastructure | ✅ Packaged |
|
| [Easy-Gate](https://github.com/wiredlush/easy-gate) | [GitHub](https://github.com/wiredlush/easy-gate) | Gateway and proxy solution | Infrastructure | ✅ Packaged |
|
||||||
| [ConsulDemocracy](https://github.com/consuldemocracy/consuldemocracy) | [GitHub](https://github.com/consuldemocracy/consuldemocracy) | Open-source citizen participation platform | Collaboration | ✅ Packaged
|
| [ConsulDemocracy](https://github.com/consuldemocracy/consuldemocracy) | [GitHub](https://github.com/consuldemocracy/consuldemocracy) | Open-source citizen participation platform | Collaboration | ✅ Packaged
|
||||||
| [BOINC](https://github.com/BOINC/boinc) | [GitHub](https://github.com/BOINC/boinc) | Open-source software for volunteer computing | Scientific-Computing |
|
| [BOINC](https://github.com/BOINC/boinc) | [GitHub](https://github.com/BOINC/boinc) | Open-source software for volunteer computing | Scientific-Computing |
|
||||||
|
|||||||
@@ -3,25 +3,23 @@
|
|||||||
> **Human read-only. Agents maintain this file automatically after each work
|
> **Human read-only. Agents maintain this file automatically after each work
|
||||||
> session.** Do not edit by hand — the next agent run will overwrite it.
|
> session.** Do not edit by hand — the next agent run will overwrite it.
|
||||||
>
|
>
|
||||||
> **Last updated:** 2026-09-06 by ZCode (GLM-5.3) — GoAlert packaged (18th; rulings synced:
|
> **Last updated:** 2026-09-06 by ZCode (GLM-5.3) — rathole REMOVED by founder
|
||||||
> GitUrlList 56→46, no-Node policy live)
|
> ruling ("we will use netbird for all enterprise network access"): package dir
|
||||||
> (#648, Infrastructure, 16th package); auth gate verdict: native OIDC via
|
> deleted, GitUrlList 46→40, completed count 19→18. Landed tickets sit in
|
||||||
> python-social-auth (OpenIdConnectAuth + SOCIAL_AUTH_OIDC_*) wired to the
|
> **Feedback** (awaiting live-Cloudron UAT); builds ON HOLD pending the
|
||||||
> platform provider; official-image wrapper of netboxcommunity/netbox
|
> founder's queue review. Standing policies: no-Node, no-open-core, no-SSO-tax,
|
||||||
> v4.6.10 (netbox-docker 5.0.2), full-stack verified (migrations, Granian,
|
> netbird for network access, RustFS makes S3 a non-blocker.
|
||||||
> gated RQ worker, OIDC login button). Session also finished #685's apply
|
|
||||||
> pass (memlimits script repairs + photos floor-limit).
|
|
||||||
|
|
||||||
## Current State: STABLE (packaging phase, ongoing)
|
## Current State: STABLE (packaging phase, ongoing)
|
||||||
|
|
||||||
Cloudron packaging pipeline is operational. 19 of 46 remaining-set applications are
|
Cloudron packaging pipeline is operational. 18 of 40 remaining-set applications are
|
||||||
packaged, committed, and pushed. Packaging templates exist for the core
|
packaged, committed, and pushed. Packaging templates exist for the core
|
||||||
patterns. The gardening protocol (this file + AGENTS.md) keeps docs in sync.
|
patterns. The gardening protocol (this file + AGENTS.md) keeps docs in sync.
|
||||||
All remaining apps now carry build tickets (#633-#678) under umbrella
|
All remaining apps now carry build tickets (#633-#678) under umbrella
|
||||||
[#632](https://projects.knownelement.com/issues/632) in Redmine project 55 —
|
[#632](https://projects.knownelement.com/issues/632) in Redmine project 55 —
|
||||||
ready for the sequential grind-driver pattern.
|
ready for the sequential grind-driver pattern.
|
||||||
|
|
||||||
## Completed Packages (19)
|
## Completed Packages (18)
|
||||||
|
|
||||||
| # | Application | Category | Pattern | Port(s) | Addons |
|
| # | Application | Category | Pattern | Port(s) | Addons |
|
||||||
|---|-------------|----------|---------|---------|--------|
|
|---|-------------|----------|---------|---------|--------|
|
||||||
@@ -35,12 +33,11 @@ ready for the sequential grind-driver pattern.
|
|||||||
| 8 | draw.io | Documentation-Tools | Official-image wrapper + auth proxy | 8080 | none (stateless) |
|
| 8 | draw.io | Documentation-Tools | Official-image wrapper + auth proxy | 8080 | none (stateless) |
|
||||||
| 9 | Windmill | Automation | Official-image wrapper + start.sh | 8000 | localstorage, postgresql |
|
| 9 | Windmill | Automation | Official-image wrapper + start.sh | 8000 | localstorage, postgresql |
|
||||||
| 10 | Easy-Gate | Infrastructure | Multi-stage (Go) + auth proxy | 8080 | localstorage |
|
| 10 | Easy-Gate | Infrastructure | Multi-stage (Go) + auth proxy | 8080 | localstorage |
|
||||||
| 11 | Rathole | Infrastructure | Pre-compiled binaries + auth proxy | 8000, 2333, 5200-5299 | localstorage |
|
| 11 | Database Gateway | Infrastructure | Multi-stage (Go, CGO) | 8080 | localstorage, postgresql |
|
||||||
| 12 | Database Gateway | Infrastructure | Multi-stage (Go, CGO) | 8080 | localstorage, postgresql |
|
| 12 | FX | DevOps-Tools | Pre-compiled binaries + auth proxy | 8000 | localstorage |
|
||||||
| 13 | FX | DevOps-Tools | Pre-compiled binaries + auth proxy | 8000 | localstorage |
|
| 13 | ChirpStack | Infrastructure | Official-image wrapper | 8080 | localstorage, postgresql, redis |
|
||||||
| 14 | ChirpStack | Infrastructure | Official-image wrapper | 8080 | localstorage, postgresql, redis |
|
| 14 | eLabFTW | Business-Apps | Official-image wrapper | 443 | localstorage, mysql, ldap |
|
||||||
| 15 | eLabFTW | Business-Apps | Official-image wrapper | 443 | localstorage, mysql, ldap |
|
| 15 | NetBox | Infrastructure | Official-image wrapper + start.sh | 8080 | localstorage, postgresql, redis |
|
||||||
| 16 | NetBox | Infrastructure | Official-image wrapper + start.sh | 8080 | localstorage, postgresql, redis |
|
|
||||||
|
|
||||||
Each package lives in `Package-Workspace/<Category>/<app>/` and contains a
|
Each package lives in `Package-Workspace/<Category>/<app>/` and contains a
|
||||||
`Dockerfile`, `CloudronManifest.json`, `README.md`, `CHANGELOG.md`, `logo.png`,
|
`Dockerfile`, `CloudronManifest.json`, `README.md`, `CHANGELOG.md`, `logo.png`,
|
||||||
@@ -73,7 +70,6 @@ GitUrlList pruned 56 → 46 accordingly.
|
|||||||
| #647 | Fleet | Monitoring | GO-with-risk (SAML first-class; build parked pending ruling) |
|
| #647 | Fleet | Monitoring | GO-with-risk (SAML first-class; build parked pending ruling) |
|
||||||
| #648 | NetBox | Infrastructure | DONE (16th package) |
|
| #648 | NetBox | Infrastructure | DONE (16th package) |
|
||||||
| #649 | SeaTunnel | Data-Management | disposition: OUT OF SCOPE (job engine) — ruling pending |
|
| #649 | SeaTunnel | Data-Management | disposition: OUT OF SCOPE (job engine) — ruling pending |
|
||||||
| #650 | Rathole | Infrastructure | DONE (11th package) |
|
|
||||||
| #651 | Easy-Gate | Infrastructure | DONE (10th package) |
|
| #651 | Easy-Gate | Infrastructure | DONE (10th package) |
|
||||||
| #653 | ConsulDemocracy | Collaboration | DONE (17th package, grind-verified) |
|
| #653 | ConsulDemocracy | Collaboration | DONE (17th package, grind-verified) |
|
||||||
| #654 | BOINC | Scientific-Computing | disposition: OUT OF SCOPE — ruling pending |
|
| #654 | BOINC | Scientific-Computing | disposition: OUT OF SCOPE — ruling pending |
|
||||||
@@ -118,7 +114,7 @@ Full write-ups of each pattern + challenges are in [`JOURNAL.md`](JOURNAL.md).
|
|||||||
| Automation | 2 | 1/2 | windmill done (huginn, runme removed) |
|
| Automation | 2 | 1/2 | windmill done (huginn, runme removed) |
|
||||||
| Business-Apps | 4 | 2/4 | elabftw, inventree done (midday, openboxes, pimcore removed) |
|
| Business-Apps | 4 | 2/4 | elabftw, inventree done (midday, openboxes, pimcore removed) |
|
||||||
| Collaboration | 2 | 1/2 | consuldemocracy done |
|
| Collaboration | 2 | 1/2 | consuldemocracy done |
|
||||||
| Infrastructure | 6 | 5/6 | easy-gate, rathole, database-gateway, chirpstack, netbox done |
|
| Infrastructure | 5 | 4/5 | easy-gate, database-gateway, chirpstack, netbox done (rathole removed) |
|
||||||
| Data-Management | 2 | 0/2 | datahub, seatunnel |
|
| Data-Management | 2 | 0/2 | datahub, seatunnel |
|
||||||
| Security | 2 | 0/2 | tirreno pending ruling (gophish, sniperphish, sat, comply removed) |
|
| Security | 2 | 0/2 | tirreno pending ruling (gophish, sniperphish, sat, comply removed) |
|
||||||
| System-Administration | 1 | 0/1 | slurm (mender removed) |
|
| System-Administration | 1 | 0/1 | slurm (mender removed) |
|
||||||
@@ -135,7 +131,7 @@ Auth capability is a hard gate before packaging (see
|
|||||||
LDAP acceptable (risk flag), 🔄 = auth-proxy (no users), ❌ = local-only
|
LDAP acceptable (risk flag), 🔄 = auth-proxy (no users), ❌ = local-only
|
||||||
(unacceptable / blocked-on-auth).
|
(unacceptable / blocked-on-auth).
|
||||||
|
|
||||||
### Completed packages (19)
|
### Completed packages (18)
|
||||||
|
|
||||||
| App | OIDC | LDAP | Verdict | Note |
|
| App | OIDC | LDAP | Verdict | Note |
|
||||||
|-----|------|------|---------|------|
|
|-----|------|------|---------|------|
|
||||||
@@ -149,7 +145,6 @@ LDAP acceptable (risk flag), 🔄 = auth-proxy (no users), ❌ = local-only
|
|||||||
| draw.io | n/a | n/a | 🔄 proxy | **Packaged** with `httpAuth.type=proxy` (no users, stateless) |
|
| draw.io | n/a | n/a | 🔄 proxy | **Packaged** with `httpAuth.type=proxy` (no users, stateless) |
|
||||||
| Windmill | yes | no | ✅ preferred | **Packaged**; OIDC configured via Admin Settings UI (no env vars) |
|
| Windmill | yes | no | ✅ preferred | **Packaged**; OIDC configured via Admin Settings UI (no env vars) |
|
||||||
| Easy-Gate | n/a | n/a | 🔄 proxy | **Packaged** with `httpAuth.type=proxy` (no user concept; IP-subnet groups only) |
|
| Easy-Gate | n/a | n/a | 🔄 proxy | **Packaged** with `httpAuth.type=proxy` (no user concept; IP-subnet groups only) |
|
||||||
| Rathole | n/a | n/a | 🔄 proxy | **Packaged** with `httpAuth.type=proxy` on the status page; tunnels secured by mandatory per-service tokens (Noise/TLS optional) |
|
|
||||||
| Database Gateway | yes | no | ✅ preferred | **Packaged**; native OIDC-only app — platform provider env (`CLOUDRON_OIDC_*`) seeded into config.json; roles from the `groups` claim |
|
| Database Gateway | yes | no | ✅ preferred | **Packaged**; native OIDC-only app — platform provider env (`CLOUDRON_OIDC_*`) seeded into config.json; roles from the `groups` claim |
|
||||||
| FX | n/a | n/a | 🔄 proxy | **Packaged**; CLI-only FaaS tool with no user concept — pinned binary + workspace driven from the Cloudron terminal; landing page gated by `httpAuth.type=proxy` |
|
| FX | n/a | n/a | 🔄 proxy | **Packaged**; CLI-only FaaS tool with no user concept — pinned binary + workspace driven from the Cloudron terminal; landing page gated by `httpAuth.type=proxy` |
|
||||||
| ChirpStack | yes | no | ✅ preferred | **Packaged**; native `[user_authentication.openid_connect]` wired to `CLOUDRON_OIDC_*`; OIDC-registered users are non-admin — one-time `CHIRPSTACK_AUTH_MODE=internal` bootstrap links the seeded `admin` to your SSO email (README) |
|
| ChirpStack | yes | no | ✅ preferred | **Packaged**; native `[user_authentication.openid_connect]` wired to `CLOUDRON_OIDC_*`; OIDC-registered users are non-admin — one-time `CHIRPSTACK_AUTH_MODE=internal` bootstrap links the seeded `admin` to your SSO email (README) |
|
||||||
@@ -173,11 +168,11 @@ HOLD while the founder reviews the queue.**
|
|||||||
|
|
||||||
| Bucket | Tickets |
|
| Bucket | Tickets |
|
||||||
|--------|---------|
|
|--------|---------|
|
||||||
| Landed — Feedback (awaiting UAT) | #633 #639 #640 #648 #650 #651 #653 #658 #668 #669 |
|
| Landed — Feedback (awaiting UAT) | #633 #639 #640 #648 #651 #653 #658 #668 #669 |
|
||||||
| APPROVED — queued (hold) | #673 NCA Toolkit (proxy-eligible Flask API; RustFS makes S3 a non-issue) |
|
| APPROVED — queued (hold) | #673 NCA Toolkit (proxy-eligible Flask API; RustFS makes S3 a non-issue) |
|
||||||
| GO — no explicit ruling yet | #634 Tirreno (verify-only; already deployed) · #642 Rundeck (OSS LDAP, no OIDC) · #662 KillBill · #647 Fleet (SAML risk; digest banked) · #833 jamovi (new; proxy; 3-origin risk) |
|
| GO — no explicit ruling yet | #634 Tirreno (verify-only; already deployed) · #642 Rundeck (OSS LDAP, no OIDC) · #662 KillBill · #647 Fleet (SAML risk; digest banked) · #833 jamovi (new; proxy; 3-origin risk) |
|
||||||
| GO-with-risk — no ruling yet | #637 Docassemble · #643 HyperSwitch (no-node dashboard workaround needed) · #671 Resgrid (bundle RabbitMQ) |
|
| GO-with-risk — no ruling yet | #637 Docassemble · #643 HyperSwitch (no-node dashboard workaround needed) · #671 Resgrid (bundle RabbitMQ) |
|
||||||
| KILLED by rulings (this wave) | #635 Runme · #645 OpenBoxes · #656 Gophish · #661 WireViz · #638 Pimcore (open-core) · #659 Mender (SSO tax) |
|
| KILLED by rulings | #635 Runme · #645 OpenBoxes · #656 Gophish · #661 WireViz · #638 Pimcore (open-core) · #659 Mender (SSO tax) · **#650 Rathole (superseded by netbird — package dir deleted)** |
|
||||||
| → k8s queue | #636 DataHub (joins #663 #678) |
|
| → k8s queue | #636 DataHub (joins #663 #678) |
|
||||||
| OUT OF SCOPE (ruling pending) | #646 Nautilus · #649 SeaTunnel · #654 BOINC · #655 Slurm · #672 SDRangel · #675 SAT |
|
| OUT OF SCOPE (ruling pending) | #646 Nautilus · #649 SeaTunnel · #654 BOINC · #655 Slurm · #672 SDRangel · #675 SAT |
|
||||||
| Upstream gone | #657 SniperPhish (404) |
|
| Upstream gone | #657 SniperPhish (404) |
|
||||||
|
|||||||
Reference in New Issue
Block a user