Entrypoint persists the generated TLS cert fingerprint so the
properties script can read it from the main volume. The screen
shows the active network, plaintext and TLS stratum ports, the
SHA-256 fingerprint for miner pinning, and the worker username
format (BTC address plus optional worker label).
ckpool-solo validates conf btcaddress once at startup to prime the
coinbase-builder, then pays solves to the worker's stratum address.
The conf value never sees a satoshi, so use the active network's
genesis coinbase address instead of a burn placeholder.
Worker stratum username is the payout address in ckpool-solo, so the
separate field was redundant. Niche vardiff/logging/zmq knobs now
live under an Advanced group with sensible defaults.
New 'tls' union config (disabled by default) spins up an
stunnel4 process inside the container that terminates TLS on
a configurable port (3334 by default) and forwards decrypted
stratum traffic to 127.0.0.1:${STRATUM_PORT}.
Cert is self-signed, generated once on first start with a
10-year validity and persisted at /root/.kamado/tls/ so the
fingerprint stays stable across restarts. SHA-256 fingerprint
is printed to container logs on each startup so users can
pin it on their miners. Miners must connect with
verification disabled (no CA trust chain for a private pool).
Runtime image grows by ~3MB for stunnel4 + openssl. The
supervisor loop now waits on three PIDs and tears all of them
down together if any one exits.
New 'zmq-enabled' boolean (default true) makes the entrypoint
export BITCOIN_ZMQ_BLOCK=tcp://<bitcoind-host>:28332, which
kamado-api's zmqmon subscribes to for sub-second chain refresh
on the dashboard. Disable it if your bitcoind doesn't have
zmqpubhashblock exposed.
The 1-arg form tried to call effects.createDir which doesn't
exist in the 0.3.5.1 effects API, crashing config save with
'TypeError: effects.createDir is not a function'. The 3-arg
form (effects, newConfig, deps) just wires up dependencies
based on the chosen bitcoind variant without touching the
filesystem.
start-sdk pack was failing on 'Copying Assets: No such file'
because the compat volume was declared with type: assets but
had no assets/compat/ directory to populate it.
start-sdk pack discovers per-arch tarballs at docker-images/
x86_64.tar and docker-images/aarch64.tar by filename convention,
not via a manifest assets entry. Dropping the invalid
'docker-images: image.tar' assets key and reworking the Makefile
to build one type=docker tarball per arch with arm/x86 single-
arch convenience targets.
Default still builds linux/arm64/v8+linux/amd64 for shipping,
but 'make PLATFORMS=linux/amd64' skips the arm64 leg on hosts
without qemu-user-static registered.
Replaces the git-clone-at-SHA source stage with a 'FROM scratch
AS source' stage that COPYs from a named build context. The
Makefile passes '--build-context kamado=../KamadoPool' by
default; override with 'make KAMADO_SRC=/elsewhere'. No more
SHA placeholder, no GitHub dependency, no re-clone on every
build — and the image always reflects the working tree.
Previous scaffold referenced a non-existent 'make ckpool-src'
target. Rewritten to inline the real build steps from the
upstream KamadoPool repo: clone ckpool at CKPOOL_COMMIT, apply
patches/*.patch, build with the same portable CFLAGS the
ckpool Dockerfile uses. The ui and api stages now match
api/Dockerfile exactly.
Entrypoint now uses the same env-var interface as the upstream
ckpool entrypoint (POOL_BTCADDRESS, BITCOIN_RPC_*, STRATUM_PORT,
etc.) and renders ckpool.conf from the bundled template via
sed. kamado-api env vars corrected to match config.FromEnv
(BITCOIN_RPC_URL, CKPOOL_SOCKDIR, CKPOOL_LOGFILE, LISTEN_ADDR).
Exposes stratum-port in the StartOS config UI so users running
simpleproxy or another TCP forwarder can point Kamado at a
non-default port. Entrypoint substitutes the value into
ckpool.conf serverurl.
Also pins placeholder KAMADO_SHA in the Dockerfile — swap to a
real pushed commit before the first build.
Multi-stage Dockerfile clones KamadoPool at a pinned SHA, builds
ckpool and kamado-api (with embedded Svelte UI), runtime image
supervises both processes via tini + wait -n. Config covers
bitcoind mainnet/testnet4 variant, payout address, coinbase tag,
vardiff knobs, and log level. Web UI interface only — stratum
:3333 requires a router port-forward or simpleproxy workaround
because StartOS 0.3.x does not forward raw TCP on LAN.
TODO before first build: pin KAMADO_REPO + KAMADO_SHA in the
Dockerfile to a pushed commit.