11 plugins from github.com/librefang/librefang-registry plugins/. index.json / index.json.sig are signed with Arka's Ed25519 key (not upstream stats.librefang.ai). Private key is not in this repo.
34 lines
1.3 KiB
Markdown
34 lines
1.3 KiB
Markdown
# Arka plugin registry
|
||
|
||
Hosted at **https://git.arka-ai.ru/arka/plugin-registry**.
|
||
|
||
This is Arka’s plugin marketplace registry: browse via Gitea Contents API,
|
||
install gated on a **signed** `index.json` (not `stats.librefang.ai`).
|
||
|
||
Plugin code is a mirror of Official
|
||
[`librefang/librefang-registry`](https://github.com/librefang/librefang-registry)
|
||
`plugins/` (MIT). The **index signature is Arka’s**, not upstream’s.
|
||
|
||
| File | Role |
|
||
| --- | --- |
|
||
| `plugins/<name>/` | Plugin tree (`plugin.toml` + hooks) |
|
||
| `index.json` | Signed membership list (what Agent Arka forge-host fetches) |
|
||
| `index.json.sig` | Ed25519 signature over the exact bytes of `index.json` |
|
||
| `plugins-index.json` | Same bytes as `index.json` (upstream filename, convenience) |
|
||
|
||
## Trust
|
||
|
||
- Public key (base64 32-byte Ed25519): see `PUBKEY` in this repo.
|
||
- Daemon: `LIBREFANG_REGISTRY_PUBKEY=<that value>`. Do **not** set `LIBREFANG_REGISTRY_VERIFY=0` in production.
|
||
- Private key is **not** in git. Re-sign after every plugin add/remove:
|
||
|
||
```bash
|
||
bash /path/to/sign-plugin-index.sh index.json ~/.arka-registry-keys/privkey.pem
|
||
cp index.json plugins-index.json
|
||
cp index.json.sig plugins-index.json.sig
|
||
```
|
||
|
||
Anonymous raw (no token):
|
||
|
||
`https://git.arka-ai.ru/arka/plugin-registry/raw/branch/main/index.json`
|