docs: the server is on the sprite and internet-exposed
The long-standing open question "where will the server actually live" is answered for now: it stays on this sprite, bound to 0.0.0.0:8090 and published over HTTPS by the sprite proxy. Several docs asserted the opposite — HANDOFF said "127.0.0.1:8090, deliberately NOT internet-exposed (no --http-port, so the sprite proxy can't reach it)", which is flatly wrong today. The consequence is the part worth writing down: PocketBase's API rules are now the only thing between this library and the internet. There is no NAT, no VPN, no reverse proxy. So the anonymous-access curls stop being a formality, and they have to run against the PUBLIC hostname — localhost cannot tell you what the world can reach. Re-verified that way: books/shelves/bookcases LIST all 403, self-registration 403, health 200. One gap found while re-verifying, recorded but NOT fixed: users LIST answers 200 with an empty array instead of 403. Nothing is disclosed — two real accounts exist and the listRule filters both out — but it is the same wrong-signal quirk pb_hooks/main.pb.js exists to close, and that hook never listed the users collection. SPEC's offline-first rationale is amended rather than its rule: the reason is no longer residential NAT but a sprite that suspends when idle and wakes on request. The rule is unchanged and does not depend on which. server/deploy/ still documents systemd/Docker/Tailscale on home hardware; it now says up front that this is the intended end state, not what is running. Also corrected, since it was adjacent and plainly false: README still claimed the app had never run on a physical device. It has, since 2026-09-09. What is true is that no *automated* test runs on a device — there is no emulator on this box. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PPpdG8VnRfS3KkisR3HUAE
This commit is contained in:
1 parent
26f76bf0f7
commit
1385ad286f
5 files changed
+149
-26
No files matched your search
@@ -1,5 +1,14 @@
|
||||
# Deploying Bookshelf's PocketBase server
|
||||
|
||||
> **This is not what is running today.** The live server currently runs on the
|
||||
> development sprite, bound to `0.0.0.0:8090` and published over HTTPS on a
|
||||
> sprite-issued hostname — **internet-exposed**, with PocketBase's API rules as
|
||||
> its only protection (see `../README.md` § "Where the live server runs"). This
|
||||
> document describes the *intended* end state: your own hardware at home, not
|
||||
> directly exposed. Where it says PocketBase is bound to localhost and
|
||||
> unreachable from outside, that is a statement about the deployment described
|
||||
> here, not about the instance the phones are currently pointed at.
|
||||
|
||||
This assumes a spare always-on machine at home (a mini PC, NUC, Raspberry Pi,
|
||||
or an old laptop) running Linux. Pick **one** of the two run methods below —
|
||||
systemd or Docker — not both.
|
||||
|
||||
Reference in new issue
Block a user