Dynamic test environments for Bitcoin, Lightning & Cashu.
Quick start · Environments · Components · Development
Proofstorm allows any coding agent to build regtest networks on the fly, and drive them through native CLIs. Proofstorm runs the services in a private local Kubernetes runtime with an optional web GUI for viewing your networks.
Alpha: for local development and disposable test data—not production or real funds.
The CLI is storm; proofstorm also works. The short command is skipped if it
conflicts with an existing executable.
Get the current public release from proofstorm.com.
On Linux x86-64, install Docker Engine with Buildx and make sure
docker info works as your normal user. Then:
curl -fsSL https://proofstorm.com/install | sh
export PATH="$HOME/.local/bin:$PATH"
storm setup
storm doctorFrom your desired directory, launch an installed, authenticated coding agent:
storm agent open codex
storm agent open opencode
storm agent open claudePrompt the agent to build your desired regtest, or use it alongside regular reviews and scans to build and test proofs of concept.
Prefer a browser? Run storm gui. It opens your default browser and offers
launch buttons for detected native apps on macOS. Add --desktop to an agent open
command to launch a native app instead of its CLI.
To free resources while keeping your cells for later:
storm stop
storm start| Host | Public installer | Status |
|---|---|---|
| Linux x86-64 / AMD64 | Available | Docker Engine + Buildx required |
| macOS Apple Silicon / ARM64 | Available | Docker Desktop required |
The built-in catalog includes the following components and integrations. Agents can read the installed catalog for exact versions, configuration, and compatibility details.
| Component | Catalog ID | Integration |
|---|---|---|
| Bitcoin Core | bitcoin-core |
Regtest chain, RPC, persistent state |
| LND | lnd |
Lightning, BOLT11 |
| Core Lightning | cln |
Lightning, BOLT11 |
| LDK Server | ldk-server |
Experimental standalone Lightning node and native CLI |
| CDK mint | cdk |
Linked LND / CLN / gRPC processor or embedded LDK Node (BOLT11 / BOLT12), optional embedded BDK on-chain; SQLite / PostgreSQL; optional NUT-21 / NUT-22 auth |
| CDK LDK Server processor | cdk-ldk-server-processor |
Experimental gRPC BOLT11 / BOLT12 backend for CDK |
| CDK Bark processor | cdk-bark-processor |
Experimental AMD64/ARM64: persistent Bark wallet and gRPC backend for CDK, advertising bolt11, onchain and arkoor in sat (each selectable) |
| Bark server | bark-server |
Experimental AMD64/ARM64: Ark server backed by PostgreSQL and CLN/hold |
| CLN with hold | cln-hold |
Experimental AMD64/ARM64: Core Lightning with the hold-invoice plugin |
| Nutshell mint | nutshell |
LND / CLN; Redis cache; 0.21.0 supports NUT-21 / NUT-22 auth |
| Nutshell wallet | nutshell-wallet |
Persistent Cashu wallet |
| CDK CLI wallet | cdk-cli-wallet |
Cashu wallet CLI |
| Coco daemon | cocod-wallet |
Experimental Cashu wallet |
| PostgreSQL | postgresql |
Persistent database |
| Redis | redis |
Ephemeral cache |
| Keycloak | keycloak |
Test OIDC provider |
| Workspace | workspace |
Custom scripts, files and services |
Enable CDK NUT-21/22 authentication with an authentication_backend link from
cdk to keycloak (binding type: authentication, protocol: oidc). Keycloak
needs a primary database_backend link to PostgreSQL. Set
auth_max_blind_tokens on the mint to limit each blind-token issuance request
(default 50). Endpoint protection follows CDK's upstream defaults.
With SQLite primary storage, CDK stores authentication locally too; omit an
authentication database link. With PostgreSQL primary storage, add a second
database_backend link with role: authentication. Both links can target the
same PostgreSQL component: Proofstorm creates separate databases, named from
the mint component ID and link role. An optional database binding field
chooses an explicit database name. SQLite primary storage with a PostgreSQL auth
link is rejected because CDK ignores that combination.
Use native cdk-cli login and blind-auth commands through component execution
for wallet testing. Typed wallet operations against protected mints are not yet
supported.
Nutshell 0.21.0 uses the same Keycloak link. Its auth store defaults to SQLite;
an optional database_backend link with role: authentication selects
PostgreSQL independently of primary storage. Its issuance settings are
auth_max_blind_tokens (default 100) and auth_rate_limit_per_minute (default
5). Nutshell 0.20.3 authentication remains unsupported.
storm update --check
storm updateFollow the reported steps to refresh the runtime and reconnect agents; the command only installs files.
Contributors also need Rust and just. Docker is required for the runtime in both development and installed releases.
just check-quick # Formatting, shell checks, and command-dispatch tests
just check # Also runs Rust lints and hermetic tests
just dev # Builds the checkout and enters its private dev shell
storm setup
storm guiDevelopment uses the same storm commands as a release. The difference is
where its binaries and controller come from: your checkout instead of a download.
State stays under .proofstorm-dev/, separate from an installed release.
Use just dev-build to rebuild, just web-dev to watch GUI assets, and exit to
leave the dev shell. See development,
check prerequisites, releases, and
macOS release work.
MIT.