New 'tls' union config (disabled by default) spins up an
stunnel4 process inside the container that terminates TLS on
a configurable port (3334 by default) and forwards decrypted
stratum traffic to 127.0.0.1:${STRATUM_PORT}.
Cert is self-signed, generated once on first start with a
10-year validity and persisted at /root/.kamado/tls/ so the
fingerprint stays stable across restarts. SHA-256 fingerprint
is printed to container logs on each startup so users can
pin it on their miners. Miners must connect with
verification disabled (no CA trust chain for a private pool).
Runtime image grows by ~3MB for stunnel4 + openssl. The
supervisor loop now waits on three PIDs and tears all of them
down together if any one exits.
184 lines
5.7 KiB
TypeScript
184 lines
5.7 KiB
TypeScript
import { compat, types as T } from "../deps.ts";
|
|
|
|
export const getConfig: T.ExpectedExports.getConfig = compat.getConfig({
|
|
"bitcoind": {
|
|
"type": "union",
|
|
"name": "Bitcoin Core",
|
|
"description": "Select which Bitcoin Core node Kamado should use.",
|
|
"tag": {
|
|
"id": "type",
|
|
"name": "Type",
|
|
"description": "Mainnet bitcoind or the testnet4 variant.",
|
|
"variant-names": {
|
|
"bitcoind": "Bitcoin Core (mainnet)",
|
|
"bitcoind-testnet": "Bitcoin Core (testnet4)",
|
|
},
|
|
},
|
|
"default": "bitcoind",
|
|
"variants": {
|
|
"bitcoind": {
|
|
"user": {
|
|
"type": "pointer",
|
|
"name": "RPC Username",
|
|
"description": "The RPC username from Bitcoin Core.",
|
|
"subtype": "package",
|
|
"package-id": "bitcoind",
|
|
"target": "config",
|
|
"multi": false,
|
|
"selector": "$.rpc.username",
|
|
},
|
|
"password": {
|
|
"type": "pointer",
|
|
"name": "RPC Password",
|
|
"description": "The RPC password from Bitcoin Core.",
|
|
"subtype": "package",
|
|
"package-id": "bitcoind",
|
|
"target": "config",
|
|
"multi": false,
|
|
"selector": "$.rpc.password",
|
|
},
|
|
},
|
|
"bitcoind-testnet": {
|
|
"user": {
|
|
"type": "pointer",
|
|
"name": "RPC Username",
|
|
"description": "The RPC username from Bitcoin Core (testnet4).",
|
|
"subtype": "package",
|
|
"package-id": "bitcoind-testnet",
|
|
"target": "config",
|
|
"multi": false,
|
|
"selector": "$.rpc.username",
|
|
},
|
|
"password": {
|
|
"type": "pointer",
|
|
"name": "RPC Password",
|
|
"description": "The RPC password from Bitcoin Core (testnet4).",
|
|
"subtype": "package",
|
|
"package-id": "bitcoind-testnet",
|
|
"target": "config",
|
|
"multi": false,
|
|
"selector": "$.rpc.password",
|
|
},
|
|
},
|
|
},
|
|
},
|
|
"pool-address": {
|
|
"type": "string",
|
|
"name": "Payout Address",
|
|
"description":
|
|
"Bitcoin address that receives the full block reward when a block is solved. Solo mining — no fees, no splits.",
|
|
"nullable": false,
|
|
"masked": false,
|
|
"copyable": true,
|
|
},
|
|
"pool-identifier": {
|
|
"type": "string",
|
|
"name": "Coinbase Tag",
|
|
"description":
|
|
"Short string embedded in the coinbase transaction of solved blocks. Max 32 characters.",
|
|
"nullable": false,
|
|
"default": "/Kamado/",
|
|
"masked": false,
|
|
"copyable": false,
|
|
},
|
|
"stratum-port": {
|
|
"type": "number",
|
|
"name": "Stratum Port",
|
|
"description":
|
|
"TCP port the plaintext stratum server listens on inside the container. Defaults to 3333. Change this if you are running simpleproxy (or another TCP forwarder) and want Kamado to listen on a different port.",
|
|
"nullable": false,
|
|
"default": 3333,
|
|
"range": "[1,65535]",
|
|
"integral": true,
|
|
},
|
|
"tls": {
|
|
"type": "union",
|
|
"name": "Stratum TLS",
|
|
"description":
|
|
"Accept stratum connections over TLS via an stunnel sidecar. A self-signed certificate is generated on first start and persisted across restarts — miners must connect with TLS verification disabled (most firmware exposes this as 'stratum+ssl://' with a skip-verify or insecure flag).",
|
|
"tag": {
|
|
"id": "enabled",
|
|
"name": "TLS Mode",
|
|
"description": "Disable or enable TLS termination in front of stratum.",
|
|
"variant-names": {
|
|
"disabled": "Disabled",
|
|
"enabled": "Enabled (stunnel sidecar)",
|
|
},
|
|
},
|
|
"default": "disabled",
|
|
"variants": {
|
|
"disabled": {},
|
|
"enabled": {
|
|
"port": {
|
|
"type": "number",
|
|
"name": "TLS Stratum Port",
|
|
"description":
|
|
"TCP port stunnel listens on for TLS stratum connections. Forwards decrypted traffic to the plaintext stratum port locally.",
|
|
"nullable": false,
|
|
"default": 3334,
|
|
"range": "[1,65535]",
|
|
"integral": true,
|
|
},
|
|
},
|
|
},
|
|
},
|
|
"startdiff": {
|
|
"type": "number",
|
|
"name": "Starting Difficulty",
|
|
"description":
|
|
"Initial vardiff target for new miner connections. Bitaxe-class miners typically land around 16384.",
|
|
"nullable": false,
|
|
"default": 16384,
|
|
"range": "[1,*)",
|
|
"integral": true,
|
|
},
|
|
"mindiff": {
|
|
"type": "number",
|
|
"name": "Minimum Difficulty",
|
|
"description": "Floor for the vardiff algorithm.",
|
|
"nullable": false,
|
|
"default": 1000,
|
|
"range": "[1,*)",
|
|
"integral": true,
|
|
},
|
|
"maxdiff": {
|
|
"type": "number",
|
|
"name": "Maximum Difficulty",
|
|
"description": "Ceiling for the vardiff algorithm. 0 means no cap.",
|
|
"nullable": false,
|
|
"default": 0,
|
|
"range": "[0,*)",
|
|
"integral": true,
|
|
},
|
|
"dropidle": {
|
|
"type": "number",
|
|
"name": "Drop Idle (seconds)",
|
|
"description":
|
|
"Disconnect clients that have not submitted a share in this many seconds. 0 disables the idle disconnect.",
|
|
"nullable": false,
|
|
"default": 0,
|
|
"range": "[0,*)",
|
|
"integral": true,
|
|
},
|
|
"zmq-enabled": {
|
|
"type": "boolean",
|
|
"name": "Enable ZMQ Block Notifications",
|
|
"description":
|
|
"Subscribe to Bitcoin Core's hashblock ZMQ topic for sub-second chain refresh on the dashboard. Requires zmqpubhashblock to be enabled on your bitcoind — the default StartOS bitcoind package exposes it on tcp://bitcoind.embassy:28332.",
|
|
"default": true,
|
|
},
|
|
"log-level": {
|
|
"type": "enum",
|
|
"name": "Log Level",
|
|
"description": "Verbosity of the kamado-api log output.",
|
|
"values": ["debug", "info", "warn", "error"],
|
|
"value-names": {
|
|
"debug": "Debug",
|
|
"info": "Info",
|
|
"warn": "Warn",
|
|
"error": "Error",
|
|
},
|
|
"default": "info",
|
|
},
|
|
});
|