Idea: xmr-cart as a Synology package (DSM-integrated admin, own node) #2

Open
opened 2026-10-01 23:17:47 +00:00 by btcbob · 0 comments
Owner

Parked idea, not scheduled. Run xmr-cart as a Synology DSM package: your own Monero shop and your own node in a NAS you already own, with no VPS.

Why it fits

xmr-cart is PHP plus one SQLite file. DSM already provides most of what it needs:

xmr-cart needs DSM has
PHP web server Web Station + Synology PHP packages
worker/poll.php every minute Task Scheduler
Public HTTPS Built-in DDNS, reverse proxy, Let's Encrypt
A node to settle against A pruned monerod in Container Manager (about 100 GB) on the same box
Backups Hyper Backup / snapshots; the whole store is data/store.sqlite

The DSM integration

  • A desktop icon in DSM that opens the console.
  • Admin auth through the DSM login instead of xmr-cart's own passphrase. DSM lets third-party apps check the logged-in user. This removes a password and the public /admin login page.
  • The setup wizard as a DSM install screen: primary address, view key, currency, node.
  • Paid-order alerts through DSM notifications (phone app, email), not mail().

The hard parts

  • Inbound from a home connection. Port forwarding, changing residential IPs, some ISPs blocking inbound entirely. QuickConnect's relay won't serve a public site. This is where most users would get stuck.
  • Exposing the NAS. A public web app on the box with someone's family photos, a target class that has been mass-exploited before. Admin must be LAN/tailnet-only, and the storefront isolated from everything else.
  • PHP extensions. Settlement needs gmp (plus bcmath, mbstring). Not yet confirmed that Synology's PHP builds ship gmp. A container sidesteps the question.
  • DSM 7 packaging. Linux 4.4 base, packages run as their own unprivileged user, and many CPU targets. Plain PHP suffers less from this than most apps.

A safer shape

Split it. The NAS holds the admin, view key, node and database and is never public. A thin public storefront on cheap hosting only takes orders and shows the pay page, talking to the NAS over a private link (WireGuard/Tailscale). Customer data and the view key never sit on an internet-facing machine. More work than a one-box package, but it's the version to trust with real money.

Shipping options, simplest first

  1. A Container Manager setup (compose file: xmr-cart + pruned monerod) plus a short guide.
  2. A real .spk (SynoCommunity / spksrc) wrapping the same thing, with the DSM desktop icon and DSM-login admin.

Reference box: DS718+ (Celeron J3455, 4 cores with AES-NI, 6 GB, DSM 7, kernel 4.4.180).

Parked idea, not scheduled. Run xmr-cart as a Synology DSM package: your own Monero shop and your own node in a NAS you already own, with no VPS. ## Why it fits xmr-cart is PHP plus one SQLite file. DSM already provides most of what it needs: | xmr-cart needs | DSM has | |---|---| | PHP web server | Web Station + Synology PHP packages | | `worker/poll.php` every minute | Task Scheduler | | Public HTTPS | Built-in DDNS, reverse proxy, Let's Encrypt | | A node to settle against | A pruned `monerod` in Container Manager (about 100 GB) on the same box | | Backups | Hyper Backup / snapshots; the whole store is `data/store.sqlite` | ## The DSM integration - A desktop icon in DSM that opens the console. - **Admin auth through the DSM login** instead of xmr-cart's own passphrase. DSM lets third-party apps check the logged-in user. This removes a password and the public `/admin` login page. - The setup wizard as a DSM install screen: primary address, view key, currency, node. - Paid-order alerts through DSM notifications (phone app, email), not `mail()`. ## The hard parts - **Inbound from a home connection.** Port forwarding, changing residential IPs, some ISPs blocking inbound entirely. QuickConnect's relay won't serve a public site. This is where most users would get stuck. - **Exposing the NAS.** A public web app on the box with someone's family photos, a target class that has been mass-exploited before. Admin must be LAN/tailnet-only, and the storefront isolated from everything else. - **PHP extensions.** Settlement needs `gmp` (plus `bcmath`, `mbstring`). Not yet confirmed that Synology's PHP builds ship `gmp`. A container sidesteps the question. - **DSM 7 packaging.** Linux 4.4 base, packages run as their own unprivileged user, and many CPU targets. Plain PHP suffers less from this than most apps. ## A safer shape Split it. The **NAS holds the admin, view key, node and database** and is never public. A **thin public storefront** on cheap hosting only takes orders and shows the pay page, talking to the NAS over a private link (WireGuard/Tailscale). Customer data and the view key never sit on an internet-facing machine. More work than a one-box package, but it's the version to trust with real money. ## Shipping options, simplest first 1. A Container Manager setup (compose file: xmr-cart + pruned `monerod`) plus a short guide. 2. A real `.spk` (SynoCommunity / spksrc) wrapping the same thing, with the DSM desktop icon and DSM-login admin. Reference box: DS718+ (Celeron J3455, 4 cores with AES-NI, 6 GB, DSM 7, kernel 4.4.180).
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
SubGeniusFinance/xmr-cart#2
No description provided.