Local-infra patches against microcosm.blue/microcosm-rs @ 3137b07. 1. pocket binds its listener to loopback, which nothing outside the container can reach. Drop this hunk once pocket takes a --bind of its own. 2. pocket hardcodes did resolution to the public slingshot, which cannot see the local plc. Makes the host an env knob (POCKET_SLINGSHOT_URL) with upstream's url as the default, so the image still works unconfigured. --- a/pocket/src/server.rs +++ b/pocket/src/server.rs @@ -260,6 +260,6 @@ .with(CatchPanic::new()) .with(Tracing); - let listener = TcpListener::bind("127.0.0.1:3000"); + let listener = TcpListener::bind("0.0.0.0:3000"); Server::new(listener).name("pocket").run(app).await.unwrap(); } --- a/pocket/src/token.rs +++ b/pocket/src/token.rs @@ -71,8 +71,9 @@ )); } - let endpoint = - "https://slingshot.microcosm.blue/xrpc/com.bad-example.identity.resolveMiniDoc"; + let slingshot = std::env::var("POCKET_SLINGSHOT_URL") + .unwrap_or_else(|_| "https://slingshot.microcosm.blue".to_string()); + let endpoint = format!("{slingshot}/xrpc/blue.microcosm.identity.resolveMiniDoc"); let doc: MiniDoc = self .client .get(format!("{endpoint}?identifier={untrusted_did}"))