⚒Anvil
Sign in

clo / cl-site public

opened

Payments host: setup and cutover 45

opened by common-lisp.net

Dave Cooper (@dcooper) on GitLab, 2026-10-04.

The payments host (clnet/deploy/payments/, see its README) on a VM of its own (clnet/deploy/payments-vm/). This issue is the one place for what's left, so nothing depends on catching each other on IRC.

Done

  • VM recipe, first iteration: 92cfff7. Review notes are comments on that commit.
  • Kit: Cyclops is the only front door (86c15eb). Data locations can be set for a separate disk (51a7763): SITE_DATA, TLS_DIR, CYCLOPS_STATE in .env.
  • Gate image delivered to the VM as a file: cyclops-image-3df36c1a.tar.gz, sha256 82eaffadef610980dbba5b4f747af668df46ef5b7ba409170cd948fa40068177. To be moved onto PAYDATA and loaded with docker load (README, step 2).

Setup (now)

  • [ ] DNS: pay.common-lisp.net → the VM.
  • [ ] Firewall: 443 from the main host's addresses only (README, step 5: the DOCKER-USER chain or the provider's firewall).
  • [ ] Keys, copied machine to machine from future (never through chat or here):
  • clnet/data/stripe-credentials.txt → $SITE_DATA/, unchanged, owner 1000, mode 600.
  • clnet/deploy/cyclops.env → the VM's cyclops.env, with the two changes cyclops.env.example marks:
    • add CYCLOPS_STRIPE_PUBLISHABLE_KEY: the live publishable key from stripe-credentials.txt, if the pot and the donations share the Stripe account;
    • set CYCLOPS_LLM_GATE_NOTIFY_URL to https://ntfy.common-lisp.net/clnet-requests?auth= plus the same token as before.
  • [ ] .env: PAY_HOST, SITE_IPS (the main host's IPv4 and IPv6 addresses), the three data paths. Run ./setup until it says Ready.
  • [ ] The machine's fingerprint, for the gate build licensed to this host: /etc/machine-id, /sys/class/dmi/id/product_uuid, /sys/class/dmi/id/board_serial. Please send by private message, not here.

Cutover (later, in this order; README, "Moving from the main host")

  • [ ] Stop future's gate, then move its state into CYCLOPS_STATE.
  • [ ] Move donations.sexp into SITE_DATA.
  • [ ] docker compose up -d on the VM; both services healthy.
  • [ ] $TLS_DIR/cert.pem to future as /etc/apache2/clnet-payments.pem; the README's two curl checks from future.
  • [ ] Apache on future: /donate → the VM.
  • [ ] future's site: CLNET_IMAGE_LAB_GATE and CYCLOPS_REPLICAS=0 in clnet/deploy/.env.
  • [ ] Try it: the smallest donation, and a top-up of the pot.
  • [ ] After it has run a while: delete the keys and the journal on future; rotate keys if anyone with root there shouldn't keep them.
Ccommon-lisp.net

Administrator (@root) on GitLab, 2026-10-04.

Quick question as to what should happen under step (3) of the installation procedure "Unpack the kit and run ./setup". The step before just loaded a docker image into the docker store. Does that mean the tarred-up Docker image needs to be unpacked on the host as well as into a docker image?

In other words: I'm not clear what to do here.

Ccommon-lisp.net

Dave Cooper (@dcooper) on GitLab, 2026-10-05.

Nothing to unpack. The image file from step 2 is only for docker load; once loaded you can delete it or keep it as the backup. "The kit" is just clnet/deploy/payments/ in this repository:

The first ./setup makes .env and cyclops.env from the examples and clones the site into ./site. Fill those two in, run ./setup again, and it says what is still missing. The README's step 3 now says this.

Sign in to comment.