Deploy vomit-proxy at proxy.nether.im #1

Closed
opened 2026-10-04 20:18:47 +00:00 by robocub · 2 comments
Owner

The app's proxy_url default is already proxy.nether.im, but nothing answers there yet, so GIF search and sticker import fail until this is deployed. The service is ready: robocub/vomit-proxy (Node, no dependencies, 11 offline tests, Dockerfile + compose).

Steps

  • Container on cubuntu; cp .env.example .env.
  • Free Tenor key and free Klipy key (GIF search).
  • A dedicated Telegram bot from @BotFather for TELEGRAM_BOT_TOKEN (sticker calls need no permissions; keep it separate from the bridge's bot).
  • docker compose up -d --build, then curl -s localhost:8788/healthz.
  • cloudflared route proxy.nether.im -> 127.0.0.1:8788.
  • Smoke test: curl -s https://proxy.nether.im/proxy/telegram/stickers/<some_set> | head.

Later

Animated Telegram stickers need rlottie + ffmpeg in this image (see #2). That is why this is a container and not a Cloudflare Worker like upstream's proxy.


Filed with LLM assistance. This is a fork-only issue; never refile it on Commet's tracker.

The app's `proxy_url` default is already `proxy.nether.im`, but nothing answers there yet, so **GIF search and sticker import fail** until this is deployed. The service is ready: [robocub/vomit-proxy](https://nether.codes/robocub/vomit-proxy) (Node, no dependencies, 11 offline tests, Dockerfile + compose). ## Steps - [ ] Container on cubuntu; `cp .env.example .env`. - [ ] Free Tenor key and free Klipy key (GIF search). - [ ] A **dedicated** Telegram bot from @BotFather for `TELEGRAM_BOT_TOKEN` (sticker calls need no permissions; keep it separate from the bridge's bot). - [ ] `docker compose up -d --build`, then `curl -s localhost:8788/healthz`. - [ ] cloudflared route `proxy.nether.im` -> `127.0.0.1:8788`. - [ ] Smoke test: `curl -s https://proxy.nether.im/proxy/telegram/stickers/<some_set> | head`. ## Later Animated Telegram stickers need rlottie + ffmpeg in this image (see #2). That is why this is a container and not a Cloudflare Worker like upstream's proxy. --- _Filed with LLM assistance. This is a fork-only issue; never refile it on Commet's tracker._
Author
Owner

Status 2026-10-04:

  • Container created; proxy runs under systemd (deploy/vomit-proxy.service, added in 987a1f7), secrets in a root-only env file.
  • Telegram routes live-tested from inside the network: a real 34-sticker set listed, and a sticker file streamed with the correct content type. The token never appears in responses.
  • Temporary token: it currently uses an existing bot's token. Swap in a dedicated @BotFather bot later.
  • Klipy key (GIF search): deferred.
  • Public hostname proxy.nether.im: cloudflared ingress + DNS route. Waiting for an explicit go, because the tunnel restart briefly interrupts other services on the same tunnel.
Status 2026-10-04: - [x] Container created; proxy runs under systemd (`deploy/vomit-proxy.service`, added in 987a1f7), secrets in a root-only env file. - [x] Telegram routes live-tested from inside the network: a real 34-sticker set listed, and a sticker file streamed with the correct content type. The token never appears in responses. - [ ] **Temporary token:** it currently uses an existing bot's token. Swap in a dedicated @BotFather bot later. - [ ] Klipy key (GIF search): deferred. - [ ] Public hostname `proxy.nether.im`: cloudflared ingress + DNS route. Waiting for an explicit go, because the tunnel restart briefly interrupts other services on the same tunnel.
Author
Owner

Deployed 2026-10-04: https://proxy.nether.im is live (the app's default since the first fork commit, so no client change was needed).

Verified from outside the network:

  • /healthz 200; Telegram set listing 200 (real 34-sticker pack) and sticker file 200 with application/x-tgsticker; no token in any response.
  • Requests with the app's user agent (Dart/3.11 (dart:io)) and others pass Cloudflare with no challenge.
  • CORS preflight 204 with Access-Control-Allow-Origin: *.
  • Signal route returns the same bytes as Signal's CDN.
  • The tunnel restart was clean: nether.im federation, well-known, policy server and the nether.services sites all 200 before and after.

proxy.nether.services was the first choice, but the tunnel's credentials only cover the nether.im zone. Leftovers are tracked in #12. Closing.

Deployed 2026-10-04: **https://proxy.nether.im** is live (the app's default since the first fork commit, so no client change was needed). Verified from outside the network: - `/healthz` 200; Telegram set listing 200 (real 34-sticker pack) and sticker file 200 with `application/x-tgsticker`; no token in any response. - Requests with the app's user agent (`Dart/3.11 (dart:io)`) and others pass Cloudflare with no challenge. - CORS preflight 204 with `Access-Control-Allow-Origin: *`. - Signal route returns the same bytes as Signal's CDN. - The tunnel restart was clean: nether.im federation, well-known, policy server and the nether.services sites all 200 before and after. `proxy.nether.services` was the first choice, but the tunnel's credentials only cover the nether.im zone. Leftovers are tracked in #12. Closing.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
robocub/vommet#1
No description provided.