No description
  • Rust 99.7%
  • Shell 0.3%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-09-29 09:23:00 +02:00
.cargo [Fix] Connection Management 2026-09-13 20:58:41 +02:00
.forgejo/workflows [WIP] User Invites 2026-09-10 23:14:25 +02:00
client feat(settings): add synced user assets 2026-09-19 23:04:22 +02:00
communities [Updt] MTP 2026-09-06 21:57:50 +02:00
iota feat(tauth): rework TAuth 2026-09-14 19:31:37 +02:00
iota-auth Update OPAQUE credential profile handling 2026-09-29 09:23:00 +02:00
iota-cli feat(tauth): rework TAuth 2026-09-14 19:31:37 +02:00
iota-connection feat(call): persist call invites 2026-09-26 10:23:58 +02:00
iota-core feat(call): persist call invites 2026-09-26 10:23:58 +02:00
iota-daemon feat(call): persist call invites 2026-09-26 10:23:58 +02:00
iota-daemon-lib [Add] Structured Iota event logging 2026-09-25 21:27:05 +02:00
iota-identity [Fix] Bound Iota storage, relay and transport resources 2026-09-24 18:37:28 +02:00
iota-installer [WIP] User Invites 2026-09-10 23:14:25 +02:00
iota-ipc [Add] Structured Iota event logging 2026-09-25 21:27:05 +02:00
iota-logger [Add] Structured Iota event logging 2026-09-25 21:27:05 +02:00
iota-paths [fix] VerNum 2026-09-10 17:53:09 +02:00
iota-process-manager [Updt] Mtp 0.3.0 2026-08-20 17:05:43 +02:00
iota-state [Add] Replyjumps 2026-08-28 16:21:11 +02:00
iota-storage Update OPAQUE credential profile handling 2026-09-29 09:23:00 +02:00
iota-terms [fix] VerNum 2026-09-10 17:53:09 +02:00
iota-updater [Add] Structured Iota event logging 2026-09-25 21:27:05 +02:00
iota-util feat(settings): add synced user assets 2026-09-19 23:04:22 +02:00
mtp-type-maps@4f81a27820 Update OPAQUE credential profile handling 2026-09-29 09:23:00 +02:00
omikron-connector Update OPAQUE credential profile handling 2026-09-29 09:23:00 +02:00
other-iota feat(settings): add synced user assets 2026-09-19 23:04:22 +02:00
scripts [WIP] User Invites 2026-09-10 23:14:25 +02:00
static/web IotaFrontend 2025-11-18 21:21:01 +01:00
systemd [fix] VerNum 2026-09-10 17:53:09 +02:00
web-server [Fix] Limit hosted-user MTP sessions 2026-09-24 18:45:31 +02:00
web-ui [Fix] Bound Iota storage, relay and transport resources 2026-09-24 18:37:28 +02:00
.cargo_toml_backup [FIX] Web UI 2026-02-15 02:29:48 +01:00
.gitignore [Fix] IPC, cli, daemon 2026-07-21 23:05:34 +02:00
.gitmodules [Fix] Stability 2026-07-27 20:37:33 +02:00
Cargo.lock Update OPAQUE credential profile handling 2026-09-29 09:23:00 +02:00
Cargo.toml [Fix] Connection Management 2026-09-13 20:58:41 +02:00
dockerfile [Fix] IPC, cli, daemon 2026-07-21 23:05:34 +02:00
flake.lock Update mtp-type-maps submodule 2026-09-28 07:17:08 +02:00
flake.nix Preserve Iota socket across daemon restarts 2026-09-21 16:27:44 +02:00
LICENSE (chore): update license 2026-07-25 13:10:44 +02:00
Plan.md [Fix] Connection Management 2026-09-13 20:58:41 +02:00
README.md [Fix] Limit hosted-user MTP sessions 2026-09-24 18:45:31 +02:00
renovate.json Add renovate.json 2026-08-05 20:15:42 +02:00
todo.md feat(tauth): rework TAuth 2026-09-14 19:31:37 +02:00

IOTA

A lightweight, Rust-based TUI and service orchestrator for Tensamin IOTA. Iota manages users and stores their messages and communities. It can be run in a centralised, decentralised or hybrid mode.

The Iota is a work in progress.

Terminal themes

The TUI defaults to the ANSI theme. Select a theme for one invocation with --theme:

iota --theme monospace
iota --theme binary status

The available names are monospace, binary, ansi, and surface. Theme selection uses this precedence: --theme, IOTA_THEME, then ui.yaml in Iota's configuration directory. For example:

IOTA_THEME=surface iota

On Linux, the configuration file defaults to ~/.config/iota/ui.yaml (or $XDG_CONFIG_HOME/iota/ui.yaml when set):

theme: surface

An invalid ui.yaml value is reported and Iota falls back to ANSI so the TUI can still start.

Accepting terms without the TUI

Iota services do not start until the required agreements have been accepted for the deployment. Use the terminal flow to read each current document and type the document-specific acceptance phrase:

iota terms accept

For a system-managed daemon, accept its deployment-scoped terms as an account that can write the system Iota state directory (normally via sudo):

sudo iota terms accept --system

iota terms status reports the stored state, and iota terms show eula, iota terms show tos, or iota terms show privacy displays an individual document without accepting it.

Linux daemon installation

The system-managed daemon runs as the dedicated iota account and listens on /run/iota/iota.sock through socket activation. The system IPC socket is the privilege boundary. Operator access is granted through the iota-operators group, and every account admitted through that socket is authorized for the full operator-console role, including user management, identity rotation, configuration, and daemon lifecycle commands. After installing, add an account with:

usermod -aG iota-operators USER

The user must start a new login session before supplementary group membership is visible. Unix per-user deployments must set IOTA_SOCKET to an absolute path; Iota does not derive its IPC socket from XDG_RUNTIME_DIR.

Asset storage limits

storage_limits in Iota's configuration controls upload admission. Defaults are 256 MiB per asset, 2 GiB of committed assets plus active upload reservations per user, four active uploads per user, 512 MiB of free filesystem space reserved, four concurrent asset I/O workers, and 4096 blobs per user. Set these fields to match deployment capacity:

storage_limits:
  max_asset_bytes: 268435456
  max_user_asset_bytes: 2147483648
  max_active_asset_uploads_per_user: 4
  min_free_asset_storage_bytes: 536870912
  max_asset_io_workers: 4
  max_user_blobs: 4096

Replacement uploads temporarily count both old and new assets until commit.

Relay freshness

Signed relays expire after 30 days less five minutes; replay rows remain for 30 days. max_relay_future_skew_millis defaults to 300000, or five minutes, and can be reduced for deployment clock tolerance. Fixed five-minute margin keeps freshness within replay retention even if configuration changes. Timestamps use Unix milliseconds.

Asset and blob list responses contain at most 128 entries. Send the returned positive Offset as the next request cursor; Offset: 0 ends pagination. web.max_mtp_sessions defaults to 256 and limits concurrent authenticated MTP sessions. web.max_mtp_sessions_per_user defaults to four sessions per hosted user. Legacy web administration requires the non-default legacy-web-admin feature.