rename: the docs say Inkwell, and nothing else still says ThoughtSync by accident
Android / Build, or is the channel already serving this? (push) Successful in 3s
CI & Build / Build now, or wait for Android? (push) Successful in 2s
CI & Build / Python lint (push) Successful in 3s
CI & Build / TypeScript typecheck (push) Successful in 16s
Desktop (Tauri) / Build, or is the channel already serving this? (push) Successful in 4s
CI & Build / Python tests (push) Successful in 17s
CI & Build / integration (push) Successful in 50s
CI & Build / Build & push image (push) Skipped
Desktop (Tauri) / Windows installer (cross-compiled) (push) Successful in 3m14s
Desktop (Tauri) / Tauri desktop (Linux) (push) Successful in 6m2s
Desktop (Tauri) / Update manifest (push) Successful in 4s
Android / Kotlin + Rust (APK) (push) Successful in 8m36s
Android / Build, or is the channel already serving this? (push) Successful in 3s
CI & Build / Build now, or wait for Android? (push) Successful in 2s
CI & Build / Python lint (push) Successful in 3s
CI & Build / TypeScript typecheck (push) Successful in 16s
Desktop (Tauri) / Build, or is the channel already serving this? (push) Successful in 4s
CI & Build / Python tests (push) Successful in 17s
CI & Build / integration (push) Successful in 50s
CI & Build / Build & push image (push) Skipped
Desktop (Tauri) / Windows installer (cross-compiled) (push) Successful in 3m14s
Desktop (Tauri) / Tauri desktop (Linux) (push) Successful in 6m2s
Desktop (Tauri) / Update manifest (push) Successful in 4s
Android / Kotlin + Rust (APK) (push) Successful in 8m36s
Step 6 of milestone 481. README, docs/*, ci-requirements.md, the desktop and Arch READMEs, alembic.ini, .gitignore, the frontend package name, the service worker's cache name (its activate handler deletes any cache by another name, so the old one is cleaned up), and the Android names in the release body. What still says thoughtsync does so on purpose (Scribe note 5071): - the desktop data crossover (crossover.rs) and its startup log - the old-export import marker - the "Upgrading from ThoughtSync" block in .env.example, and compose's pointer to it - the packages being retired: deb conflicts/replaces thought-sync, pacman thoughtsync and thoughtsync-desktop - the Android signing keyAlias, which names a key in the existing keystore - history: shipped alembic migrations, and the test-binary hashes that ci-requirements.md records from 2026-08-18 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -1,6 +1,6 @@
|
||||
# Putting ThoughtSync on the public internet
|
||||
# Putting Inkwell on the public internet
|
||||
|
||||
ThoughtSync is built to run on a LAN and works fine there with no ceremony. Exposing
|
||||
Inkwell is built to run on a LAN and works fine there with no ceremony. Exposing
|
||||
it changes the threat model: anyone can now reach the login form, and any account is
|
||||
one guessed password away from someone's whole note history.
|
||||
|
||||
@@ -65,7 +65,7 @@ Which fix depends on where your proxy runs:
|
||||
the `ports:` block from `docker-compose.yml`. The proxy reaches the app over the
|
||||
compose network; no published port is needed at all, and this is the safest of the
|
||||
two because there is no host port to reach even from the host.
|
||||
- **Proxy on the host**: set `THOUGHTSYNC_BIND=127.0.0.1` in `.env`, so the port
|
||||
- **Proxy on the host**: set `INKWELL_BIND=127.0.0.1` in `.env`, so the port
|
||||
exists but only the host itself can use it.
|
||||
|
||||
To check which you have: `docker compose ps` shows the published ports, and
|
||||
@@ -73,12 +73,12 @@ To check which you have: `docker compose ps` shows the published ports, and
|
||||
app is still answering around the proxy. It should not be.
|
||||
|
||||
**5. Have a backup that includes the files.** Attachments are files on the
|
||||
`thoughtsync-data` volume, not rows — a `pg_dump` restores notes whose images are all
|
||||
`inkwell-data` volume, not rows — a `pg_dump` restores notes whose images are all
|
||||
gone. Back up both:
|
||||
|
||||
```
|
||||
docker compose exec -T db pg_dump -U thoughtsync thoughtsync > notes.sql
|
||||
docker run --rm -v thoughtsync-data:/d -v "$PWD":/out alpine tar czf /out/media.tgz -C /d .
|
||||
docker compose exec -T db pg_dump -U inkwell inkwell > notes.sql
|
||||
docker run --rm -v inkwell-data:/d -v "$PWD":/out alpine tar czf /out/media.tgz -C /d .
|
||||
```
|
||||
|
||||
## What the app already does
|
||||
@@ -132,7 +132,7 @@ know. They are the reason not to hand out open registration to strangers.
|
||||
|
||||
The app allows plain HTTP so a self-hosted server on a LAN is usable at all — Android
|
||||
blocks cleartext by default from API 28, and `http://192.168.1.10:8000` is exactly the
|
||||
case ThoughtSync is built for. Over the public internet, link the phone to the
|
||||
case Inkwell is built for. Over the public internet, link the phone to the
|
||||
**HTTPS** hostname. The sync screen shows a warning before any credential field
|
||||
whenever the address it probed was `http://`; on a public network that warning means
|
||||
what it says.
|
||||
|
||||
Reference in New Issue
Block a user