A machine's role is now the interview's first question and the one answer Panama records. Servers get the same shell minus the screen: core packages, nvm, Bun, Claude Code and Codex (desktops get Codex too), linger, rootless ports from 80, firewalld, the nginx-bridge network, and a nightly image updater that replaced watchtower for cause. server/containers/ carries junior's 23 compose services -- secrets moved to per-machine .env files that never enter this public repo, every transformed compose proven to render byte-identical to what is live. 'panama server' enables, disables and relinks them; nothing here restarts a running service. 'boot --server' walks a fresh VPS from its root login to a normal install. Five new contracts pin the secrets rule, the catalog's shape, panama-server's behavior, the role plumbing, and the dotfile classification. Claude-Session: https://claude.ai/code/session_01NU5JGiN3JfzqrLQB6wmJ1E
22 lines
490 B
Desktop File
22 lines
490 B
Desktop File
[Unit]
|
|
RequiresMountsFor=/home/gib/Media
|
|
Description=Podman Compose: Nginx Proxy Manager
|
|
After=network-online.target podman-postgresql.service
|
|
Wants=network-online.target
|
|
StartLimitIntervalSec=300
|
|
StartLimitBurst=3
|
|
|
|
[Service]
|
|
Type=oneshot
|
|
WorkingDirectory=%h/Server/Nginx_Proxy_Manager
|
|
ExecStart=/usr/bin/podman compose up -d
|
|
ExecStop=/usr/bin/podman compose down
|
|
RemainAfterExit=yes
|
|
TimeoutStartSec=300
|
|
TimeoutStopSec=60
|
|
Restart=on-failure
|
|
RestartSec=30
|
|
|
|
[Install]
|
|
WantedBy=default.target
|