run it
target: a capsule of your own, serving. ten minutes, mostly the download.
get, verify, run
the release page carries every artefact, each with a minisign signature and a checksum:
the current release, with every artefact
minisign -Vm SHA256SUMS -P RWQ8yH+Afj6YnCB5dOP+vbhvFT6DQhHBzmkC5oAY9gIrv0+vyAP+qQAw sha256sum -c SHA256SUMS ./usv
zero configuration is a supported configuration, not a degraded one. first start mints the capsule's identity, writes a starter page, and serves it: gemini immediately, the web when you point it at an http address.
prefer questions to a config file? "usv init" is a terminal wizard.
on a cloudron
usv is a community app. dashboard, app store, "add custom app", "community app", paste:
https://raw.githubusercontent.com/OrcVole/unseen-servant/main/CloudronVersions.json
installs made this way receive updates automatically. 256 MiB, no database. the gemini port is fixed at 1965 because every client assumes it; gopher, spartan, nex and finger are optional ports you switch on in the app's settings. the dashboard tile opens the web mirror, and the state directory rides in platform backups, so identity survives updates, restores and domain moves.
every other package
deb, rpm, aur, nix, a distroless container image, and the plain tarball: one page, each with its get and verify lines and its quirks.
packages: get and verify, one by one
configuration, when you want some
one file. every setting has a working default and the file does not need to exist. an unknown key is a startup error, not a warning: a typo in a security-relevant setting must never fail open by being ignored.
reload re-reads configuration and certificates without dropping connections. an invalid edit is refused and the previous configuration keeps running, so a mistake cannot take the capsule down.
upgrading
replace the binary, package or image. state lives outside the code and is not touched. identity is never regenerated by an upgrade; readers who pinned your certificate stay undisturbed.