Skip to content
Proud to collaborate with Microsoft for Startups

Apphost ​

WorkflowTypeDescription
apphost.addon.applyDagEnsure Nostr Buzz (WebSocket relay + Redis + MinIO) on a claimed AppHost site: Redis, MinIO, and relay are created if missing and updated on re-apply. This is not native Chat Relay, not Orkestia AppData conversations, and not DPWAI Chat Relay REST/SSE. Postgres is the site's AppData instance (not Neon, not in-cluster). Forces the Machine always-on. Does not steal the CloudFront site host.
apphost.addon.ensure-checkAtomicConfirm Buzz Redis, MinIO, and relay exist and are Ready (not crashlooping behind a leftover replica)
apphost.addon.logsDagRead the last lines of the Buzz relay pod on a claimed AppHost site. One-shot tail, not a stream.
apphost.addon.logs-pickAtomicPick the Buzz relay pod for a one-shot log tail.
apphost.addon.media.contractDagSupported upload/download path for Buzz attachments on a claimed site: durable MinIO PVC, Buzz /media with NIP-42, not shared document workflows. No kubeconfig. No secrets.
apphost.addon.media.contract-describeAtomicProject the supported Buzz /media contract. No secrets.
apphost.addon.object.authorizeAtomicRefuse attachment verbs unless an end-user principal matches the site app
apphost.addon.object.putDagUpload an attachment onto this site's MinIO PVC. Requires an end-user principal and a visible conversation row (membership RLS). Not data.appdata.document.*. No kubeconfig. No secrets in output.
apphost.addon.object.put-executeAtomicPUT bytes onto the site MinIO PVC. No secret keys in output.
apphost.addon.object.sign-getDagMint a short-lived GET URL for an attachment on this site's MinIO PVC. Requires an end-user principal and a visible conversation row. Not data.appdata.document.*.
apphost.addon.object.sign-get-executeAtomicMint a short-lived GET URL for a site MinIO object. No secret keys in output.
apphost.addon.prepareAtomicResolve a hosted site, force the Machine always-on, and build chart-shaped Nostr Buzz manifests (WebSocket relay + Redis + MinIO; Postgres is AppData) pinned to pool apphost. Not native Chat Relay and not DPWAI Chat Relay REST/SSE.
apphost.addon.pvc-bound-checkAtomicRefuse to start MinIO or relay until MinIO and git PVCs are Bound
apphost.addon.removeDagRemove Buzz relay, Redis, and MinIO from a claimed AppHost site and restore Ingress / to the web process. AppData Secret stays. MinIO and relay-git PVCs are deleted (this is the destroy path).
apphost.addon.resolveAtomicResolve a claimed AppHost site to its namespace and the platform Kubernetes connection for Buzz manage verbs.
apphost.addon.restartDagRestart Buzz relay, Redis, and MinIO on a claimed AppHost site. MinIO attachments and relay git survive on PVCs. Redis emptyDir and git pack cache may reset. No kubeconfig.
apphost.addon.statusDagLive Buzz status for a claimed AppHost site: transport (relay Ready), persistence (Machine / AppData state), and whether the identity app has an end-user agent bound. Redis and MinIO are ClusterIP. The Buzz host is not probed over the public internet. No kubeconfig. No secrets.
apphost.addon.status-summarizeAtomicProject Buzz ready counts from the cluster snapshot. No public HTTP. No secrets.
apphost.database.attachDagAttach Orkestia AppData Postgres (the app's own instance on dbhost) as DATABASE_URL on a claimed AppHost site. Not Neon.
apphost.database.prepareAtomicResolve a hosted site to its identity app and namespace for AppData Postgres attach. Neon is not used.
apphost.image.buildLinearSchedule an Azure Container Registry task for a public GitHub source and poll until the image is pushed. No customer cloud connection.
apphost.machine.claimAtomicClaim hosted compute for an AppHost site: enforce subscription and live-machine quotas, persist desired_status=allocated. Default placement is shared (no AKS pool). Idempotent per live site.
apphost.machine.destroyAtomicAsk reconcile to delete the Machine node and stop metering
apphost.machine.getAtomicFetch a single hosted Machine
apphost.machine.listAtomicPaginated list of an organization's hosted Machines
apphost.machine.reconcileAtomicConverge hosted Machine desired_status. Shared placement stamps without Azure. Dedicated pools still need platform Azure env.
apphost.machine.sleepAtomicAsk reconcile to deallocate a sleepable Machine so machine-minutes stop. Rejected for always_on.
apphost.machine.wakeAtomicAsk reconcile to allocate a sleeping or pending Machine again
apphost.release.createAtomicCreate a pending_upload HostedRelease for a claimed apphost site and return a presigned S3 POST (size-capped) for the bundle upload. POST every upload_fields key (including x-amz-credential and x-amz-security-token), then file=@bundle.zip last. Publish/activation is a separate workflow (apphost.release.publish).
apphost.release.publishAtomicPublish an uploaded apphost release bundle: verify bundle.zip against the byte quota, safely extract it into the immutable release prefix, point the CloudFront KVS slug entry at it, register the site's /callback on the identity app client, and prune published releases beyond the retention window.
apphost.release.rollbackAtomicRoll a hosted site back to a previously published release: verify the immutable S3 prefix is still servable, repoint active_release_uuid, and flip the CloudFront KVS routing entry.
apphost.site.claimAtomicClaim <slug>.app.orkestia.dev for a provisioned, live-mode identity app: enforce subscription + identity-app preconditions, validate slug uniqueness and the per-org site quota, then create the hosted_site row (mode=active, no release yet). Idempotent per identity app; slug is immutable after claim.
apphost.site.deleteAtomicDelete a hosted site: remove the CloudFront KVS mapping and S3 release prefix, drop the hosted_site row, and free the organization's site quota
apphost.site.domain-attachLinearAttach a custom hostname to a hosted site: request ACM covering *.app.orkestia.dev plus the hostname, return DNS validation records, poll until ISSUED, then add the CloudFront alias and KVS routing key.
apphost.site.domain-detachAtomicDetach a custom hostname from a hosted site: drop the CloudFront alias and KVS routing key, then delete the hosted_site_domain row.
apphost.site.domain-listAtomicList custom hostnames attached to a hosted site (ACM/CloudFront attach status)
apphost.site.getAtomicFetch a single hosted site (by site_uuid or identity_app_uuid) with its serving URL
apphost.site.listAtomicPaginated list of an organization's hosted sites with their serving URLs
apphost.site.release-listAtomicPaginated release history for a hosted site, flagging the currently served release
apphost.site.set-modeAtomicSwitch a hosted site between active, redirect, and suspended serving modes
apphost.source.inspectAtomicInspect a public GitHub repository for AppHost source launch. Dockerfile wins; otherwise package.json with scripts.start. Private repos and git hosts other than GitHub are rejected.
apphost.source.launchDagLoad a public GitHub repository, build from Dockerfile or package.json on platform ACR, and serve the image in the site's isolated namespace on the shared apphost pool. No customer kubeconfig or cloud connection.
apphost.web.ackAtomicNo-op compensate for apphost.web.deploy. Shared compute stays claimed; teardown is apphost.machine.destroy.
apphost.web.deployDagLaunch an app on a claimed AppHost site from a container image (or registry repo). No customer connection. Pins the Deployment to the shared apphost pool and serves https://<slug>.app.orkestia.dev.
apphost.web.prepareAtomicResolve a hosted site and container image, claim shared compute if needed, and build Namespace/Deployment/Service/Ingress manifests pinned to pool apphost.