rename: the docs say Inkwell, and nothing else still says ThoughtSync by accident
Android / Build, or is the channel already serving this? (push) Successful in 3s
CI & Build / Build now, or wait for Android? (push) Successful in 2s
CI & Build / Python lint (push) Successful in 3s
CI & Build / TypeScript typecheck (push) Successful in 16s
Desktop (Tauri) / Build, or is the channel already serving this? (push) Successful in 4s
CI & Build / Python tests (push) Successful in 17s
CI & Build / integration (push) Successful in 50s
CI & Build / Build & push image (push) Skipped
Desktop (Tauri) / Windows installer (cross-compiled) (push) Successful in 3m14s
Desktop (Tauri) / Tauri desktop (Linux) (push) Successful in 6m2s
Desktop (Tauri) / Update manifest (push) Successful in 4s
Android / Kotlin + Rust (APK) (push) Successful in 8m36s

Step 6 of milestone 481. README, docs/*, ci-requirements.md, the desktop and
Arch READMEs, alembic.ini, .gitignore, the frontend package name, the service
worker's cache name (its activate handler deletes any cache by another name, so
the old one is cleaned up), and the Android names in the release body.

What still says thoughtsync does so on purpose (Scribe note 5071):
- the desktop data crossover (crossover.rs) and its startup log
- the old-export import marker
- the "Upgrading from ThoughtSync" block in .env.example, and compose's pointer
  to it
- the packages being retired: deb conflicts/replaces thought-sync, pacman
  thoughtsync and thoughtsync-desktop
- the Android signing keyAlias, which names a key in the existing keystore
- history: shipped alembic migrations, and the test-binary hashes that
  ci-requirements.md records from 2026-08-18

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-10-06 14:35:02 -04:00
co-authored by Claude Opus 5.5
parent 81cd719327
commit 6d082b2ad8
13 changed files with 67 additions and 65 deletions
+10 -10
View File
@@ -1,6 +1,6 @@
# Getting the Android app onto your server
ThoughtSync's server hands out the Android client it syncs with. Once an APK is in
Inkwell's server hands out the Android client it syncs with. Once an APK is in
place, anyone with an account on that server can download it from **Account →
Linked devices**, and linked phones can update themselves from it.
@@ -34,7 +34,7 @@ pinning.
## Overriding it
If you want a specific build — testing something, or holding back — drop it in
`/var/thoughtsync/client/` and it wins over the image's copy.
`/var/inkwell/client/` and it wins over the image's copy.
That directory is shared with the desktop clients the server hands out, and
**precedence is decided per platform**: dropping in an APK overrides the baked APK
@@ -44,14 +44,14 @@ Two files, both required:
| File | What it is |
| --- | --- |
| `thoughtsync.apk` | the client |
| `thoughtsync-android.json` | `{version_name, version_code, size, sha256}` |
| `inkwell.apk` | the client |
| `inkwell-android.json` | `{version_name, version_code, size, sha256}` |
The sidecar exists because an APK keeps its version in a binary manifest that
needs the Android build tools to read. CI writes it beside the APK, where the
real values are already known.
`/var/thoughtsync` is the same volume that holds attachments (`Config.DATA_DIR`),
`/var/inkwell` is the same volume that holds attachments (`Config.DATA_DIR`),
so a build dropped there survives container recreation — and survives an image
upgrade, which is the point of an override.
@@ -59,10 +59,10 @@ Both files are published to the rolling dev-channel release (tag `dev-rolling`)
on every green Android build:
```sh
REPO=https://git.fabledsword.com/bvandeusen/thoughtsync
REPO=https://git.fabledsword.com/bvandeusen/inkwell
TOKEN=... # a Fabled-Git token with read access; the instance is private
for f in thoughtsync.apk thoughtsync-android.json; do
for f in inkwell.apk inkwell-android.json; do
curl -fsSL -H "Authorization: token $TOKEN" \
-o "/tmp/$f" "$REPO/releases/download/dev-rolling/$f"
done
@@ -70,8 +70,8 @@ done
# Copy the sidecar LAST. A sidecar that does not match the APK beside it is not a
# client, so a half-finished copy falls back to the image's build rather than
# advertising a lie.
docker compose cp /tmp/thoughtsync.apk app:/var/thoughtsync/client/
docker compose cp /tmp/thoughtsync-android.json app:/var/thoughtsync/client/
docker compose cp /tmp/inkwell.apk app:/var/inkwell/client/
docker compose cp /tmp/inkwell-android.json app:/var/inkwell/client/
```
To go back to whatever the image ships, delete both files.
@@ -88,7 +88,7 @@ offering a button that fails.
## What happens if you get it wrong
All of these describe an override in `/var/thoughtsync/client/`. A broken
All of these describe an override in `/var/inkwell/client/`. A broken
override does not take the feature away — it falls through to the build the image
shipped with, which is the whole reason precedence runs in that direction.
+7 -7
View File
@@ -1,6 +1,6 @@
# Putting ThoughtSync on the public internet
# Putting Inkwell on the public internet
ThoughtSync is built to run on a LAN and works fine there with no ceremony. Exposing
Inkwell is built to run on a LAN and works fine there with no ceremony. Exposing
it changes the threat model: anyone can now reach the login form, and any account is
one guessed password away from someone's whole note history.
@@ -65,7 +65,7 @@ Which fix depends on where your proxy runs:
the `ports:` block from `docker-compose.yml`. The proxy reaches the app over the
compose network; no published port is needed at all, and this is the safest of the
two because there is no host port to reach even from the host.
- **Proxy on the host**: set `THOUGHTSYNC_BIND=127.0.0.1` in `.env`, so the port
- **Proxy on the host**: set `INKWELL_BIND=127.0.0.1` in `.env`, so the port
exists but only the host itself can use it.
To check which you have: `docker compose ps` shows the published ports, and
@@ -73,12 +73,12 @@ To check which you have: `docker compose ps` shows the published ports, and
app is still answering around the proxy. It should not be.
**5. Have a backup that includes the files.** Attachments are files on the
`thoughtsync-data` volume, not rows — a `pg_dump` restores notes whose images are all
`inkwell-data` volume, not rows — a `pg_dump` restores notes whose images are all
gone. Back up both:
```
docker compose exec -T db pg_dump -U thoughtsync thoughtsync > notes.sql
docker run --rm -v thoughtsync-data:/d -v "$PWD":/out alpine tar czf /out/media.tgz -C /d .
docker compose exec -T db pg_dump -U inkwell inkwell > notes.sql
docker run --rm -v inkwell-data:/d -v "$PWD":/out alpine tar czf /out/media.tgz -C /d .
```
## What the app already does
@@ -132,7 +132,7 @@ know. They are the reason not to hand out open registration to strangers.
The app allows plain HTTP so a self-hosted server on a LAN is usable at all — Android
blocks cleartext by default from API 28, and `http://192.168.1.10:8000` is exactly the
case ThoughtSync is built for. Over the public internet, link the phone to the
case Inkwell is built for. Over the public internet, link the phone to the
**HTTPS** hostname. The sync screen shows a warning before any credential field
whenever the address it probed was `http://`; on a public network that warning means
what it says.
+3 -3
View File
@@ -1,4 +1,4 @@
# ThoughtSync sync protocol
# Inkwell sync protocol
The contract the local-first native clients (Tauri desktop, Android) implement
against. The server is the **sync hub**: each client keeps a full local store
@@ -38,8 +38,8 @@ token, or even has an account:
```
The client identifies itself on every request with
`X-ThoughtSync-Client: thoughtsync-desktop/<app version>` and
`X-ThoughtSync-Protocol: <n>`.
`X-Inkwell-Client: inkwell-desktop/<app version>` and
`X-Inkwell-Protocol: <n>`.
### `sync_features` — why versions alone aren't enough