Voice-note capture as the primary mobile input channel. AudioPen polishes on their cloud, POSTs to a self-hosted receiver on the desktop (exposed via Tailscale Funnel so no router ports open and nothing behind Authentik). The receiver writes to inbox/raw/; a bash normaliser wraps each drop in frontmatter and moves it to inbox/; /triage-inbox routes them from there. scripts/audiopen-ingest.sh — 80-line bash normaliser. Idempotent; safe to re-run. Extracts title, slugifies, computes capture timestamp from mtime, rewrites with fleeting-note frontmatter. scripts/audiopen-webhook/main.py — stdlib-only Python HTTP server. Zero pip deps; binds to 127.0.0.1 by default. Accepts flexible payload shapes (title/name + body/output/summary/polished/ orig_transcript) so AudioPen version drift is logged rather than silently dropped. scripts/audiopen-webhook/*.example — systemd user-unit templates for the receiver and the path/service pair that fires the ingest wrapper on inbox/raw/ changes. scripts/pyproject.toml + README.md — Python venv convention. Zero deps today; venv location reserved at scripts/.venv/ (gitignored), manifest at scripts/pyproject.toml, bootstrap documented for both plain pip and uv. Optional-dependencies groups let individual tools pull what they need without bloating the whole env. docs/setup/audiopen.md — full setup guide: generating the shared secret, installing the systemd units, pairing with Tailscale Funnel, configuring AudioPen's webhook, and the IMAP-fallback path for setups that can't run a public-reachable receiver. docs/setup/sync.md — companion guide: Gitea SSH remote (works even with Authentik gating HTTPS), obsidian-git plugin configuration, Syncthing desktop↔phone pairing with the critical .stignore patterns, and the three phone-role tiers so the user can pick Tier 1 / 2 / 3 at their own pace. .gitignore gains **/.venv/, **/venv/, **/__pycache__/, and *.pyc so nobody accidentally commits a materialised environment. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
37 lines
1.1 KiB
Plaintext
37 lines
1.1 KiB
Plaintext
# audiopen-webhook user systemd unit — example
|
|
#
|
|
# Install to ~/.config/systemd/user/audiopen-webhook.service, then:
|
|
# systemctl --user daemon-reload
|
|
# systemctl --user enable --now audiopen-webhook.service
|
|
#
|
|
# Check logs:
|
|
# journalctl --user -u audiopen-webhook.service -f
|
|
#
|
|
# The shared secret lives in ~/.config/audiopen-webhook/env (chmod 600).
|
|
# Example env file contents:
|
|
# AUDIOPEN_WEBHOOK_SECRET=<random-32-char-string>
|
|
# # Optional overrides:
|
|
# # AUDIOPEN_WEBHOOK_HOST=127.0.0.1
|
|
# # AUDIOPEN_WEBHOOK_PORT=8765
|
|
# # COUNCIL_INBOX_RAW=/var/mnt/data/projects/council/inbox/raw
|
|
|
|
[Unit]
|
|
Description=AudioPen webhook receiver (writes to council/inbox/raw)
|
|
After=network-online.target
|
|
Wants=network-online.target
|
|
|
|
[Service]
|
|
Type=simple
|
|
EnvironmentFile=%h/.config/audiopen-webhook/env
|
|
ExecStart=/usr/bin/python3 %h/projects/council/scripts/audiopen-webhook/main.py
|
|
Restart=on-failure
|
|
RestartSec=5
|
|
# Narrow permissions:
|
|
NoNewPrivileges=true
|
|
ProtectSystem=strict
|
|
ProtectHome=read-only
|
|
ReadWritePaths=/var/mnt/data/projects/council/inbox/raw
|
|
|
|
[Install]
|
|
WantedBy=default.target
|