Merge pull request 'module fixes from the whole-mesh dry-run: fail2ban capability + tool-runtime credential wiring' (#20) from feat/module-cred-fixes into main

This commit was merged in pull request #20.
This commit is contained in:
2026-09-08 18:45:24 +02:00
15 changed files with 99 additions and 15 deletions
+9 -1
View File
@@ -43,6 +43,14 @@ function meshConfig(file?: string): Record<string, string> {
catch { return {}; } catch { return {}; }
} }
/** Read a secret the mesh mounted at a file path (an own-secret delivered by `secret accept`);
* absent or unreadable yields undefined so callers fall back rather than crash. */
function readSecret(file?: string): string | undefined {
if (!file) return undefined;
try { return readFileSync(file, "utf8").trim(); }
catch { return undefined; }
}
export class BazarrClient { export class BazarrClient {
readonly baseUrl: string; readonly baseUrl: string;
@@ -58,7 +66,7 @@ export class BazarrClient {
static fromEnv(env: NodeJS.ProcessEnv = process.env): BazarrClient { static fromEnv(env: NodeJS.ProcessEnv = process.env): BazarrClient {
const cfg = meshConfig(env.MESH_BAZARR_CONFIG_FILE); const cfg = meshConfig(env.MESH_BAZARR_CONFIG_FILE);
const url = cfg.url ?? env.MESH_BAZARR_URL; const url = cfg.url ?? env.MESH_BAZARR_URL;
const apiKey = cfg.apiKey ?? env.MESH_BAZARR_API_KEY; const apiKey = cfg.apiKey ?? readSecret(env.MESH_BAZARR_API_KEY_FILE) ?? env.MESH_BAZARR_API_KEY;
if (!url) throw new Error("no Bazarr URL — set MESH_BAZARR_URL"); if (!url) throw new Error("no Bazarr URL — set MESH_BAZARR_URL");
if (!apiKey) throw new Error("no Bazarr API key — set MESH_BAZARR_API_KEY"); if (!apiKey) throw new Error("no Bazarr API key — set MESH_BAZARR_API_KEY");
return new BazarrClient(url, apiKey); return new BazarrClient(url, apiKey);
+4 -1
View File
@@ -8,7 +8,8 @@
"module.bazarr.subtitle.downloaded" "module.bazarr.subtitle.downloaded"
], ],
"own-secrets": { "own-secrets": {
"broker": "/var/lib/mesh/bazarr/broker" "broker": "/var/lib/mesh/bazarr/broker",
"api-key": "/var/lib/mesh/bazarr/api-key"
}, },
"listens": [ "listens": [
{ {
@@ -87,12 +88,14 @@
"network": "host", "network": "host",
"volumes": [ "volumes": [
"/var/lib/mesh/bazarr/broker:/run/secrets/broker:ro", "/var/lib/mesh/bazarr/broker:/run/secrets/broker:ro",
"/var/lib/mesh/bazarr/api-key:/run/secrets/api-key:ro",
"/var/lib/mesh/bazarr/config.json:/run/config/config.json:ro", "/var/lib/mesh/bazarr/config.json:/run/config/config.json:ro",
"/services/bazarr/config:/var/lib/bazarr/config:ro" "/services/bazarr/config:/var/lib/bazarr/config:ro"
], ],
"env": { "env": {
"MESH_BROKER_FILE": "/run/secrets/broker", "MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_BAZARR_URL": "http://127.0.0.1:6767", "MESH_BAZARR_URL": "http://127.0.0.1:6767",
"MESH_BAZARR_API_KEY_FILE": "/run/secrets/api-key",
"MESH_BAZARR_CONFIG_FILE": "/run/config/config.json", "MESH_BAZARR_CONFIG_FILE": "/run/config/config.json",
"MESH_BAZARR_CONFIG_DIR": "/var/lib/bazarr/config" "MESH_BAZARR_CONFIG_DIR": "/var/lib/bazarr/config"
}, },
+1 -1
View File
@@ -2,7 +2,7 @@
"module": "fail2ban", "module": "fail2ban",
"version": "1", "version": "1",
"capabilities": [ "capabilities": [
"intrusion-prevention" "firewall"
], ],
"claims": [ "claims": [
{ {
+9 -1
View File
@@ -27,6 +27,14 @@ function meshConfig(file?: string): Record<string, string> {
catch { return {}; } catch { return {}; }
} }
/** Read a secret the mesh mounted at a file path (an own-secret delivered by `secret accept`);
* absent or unreadable yields undefined so callers fall back rather than crash. */
function readSecret(file?: string): string | undefined {
if (!file) return undefined;
try { return readFileSync(file, "utf8").trim(); }
catch { return undefined; }
}
export class HomeAssistantClient { export class HomeAssistantClient {
readonly baseUrl: string; readonly baseUrl: string;
@@ -45,7 +53,7 @@ export class HomeAssistantClient {
static fromEnv(env: NodeJS.ProcessEnv = process.env): HomeAssistantClient { static fromEnv(env: NodeJS.ProcessEnv = process.env): HomeAssistantClient {
const cfg = meshConfig(env.MESH_HOMEASSISTANT_CONFIG_FILE); const cfg = meshConfig(env.MESH_HOMEASSISTANT_CONFIG_FILE);
const url = cfg.url ?? env.MESH_HOMEASSISTANT_URL ?? `http://127.0.0.1:${env.HOMEASSISTANT_PORT ?? "8123"}`; const url = cfg.url ?? env.MESH_HOMEASSISTANT_URL ?? `http://127.0.0.1:${env.HOMEASSISTANT_PORT ?? "8123"}`;
const token = cfg.token ?? env.MESH_HOMEASSISTANT_TOKEN; const token = cfg.token ?? readSecret(env.MESH_HOMEASSISTANT_TOKEN_FILE) ?? env.MESH_HOMEASSISTANT_TOKEN;
if (!token) throw new Error("no Home Assistant token — set MESH_HOMEASSISTANT_TOKEN"); if (!token) throw new Error("no Home Assistant token — set MESH_HOMEASSISTANT_TOKEN");
return new HomeAssistantClient(url, token); return new HomeAssistantClient(url, token);
} }
+4 -1
View File
@@ -8,7 +8,8 @@
"module.home-assistant.state.changed" "module.home-assistant.state.changed"
], ],
"own-secrets": { "own-secrets": {
"broker": "/var/lib/mesh/home-assistant/broker" "broker": "/var/lib/mesh/home-assistant/broker",
"token": "/var/lib/mesh/home-assistant/token"
}, },
"listens": [ "listens": [
{ {
@@ -61,12 +62,14 @@
"network": "host", "network": "host",
"volumes": [ "volumes": [
"/var/lib/mesh/home-assistant/broker:/run/secrets/broker:ro", "/var/lib/mesh/home-assistant/broker:/run/secrets/broker:ro",
"/var/lib/mesh/home-assistant/token:/run/secrets/token:ro",
"/var/lib/mesh/home-assistant/config.json:/run/config/config.json:ro", "/var/lib/mesh/home-assistant/config.json:/run/config/config.json:ro",
"/services/home-assistant/config:/var/lib/home-assistant/config:ro" "/services/home-assistant/config:/var/lib/home-assistant/config:ro"
], ],
"env": { "env": {
"MESH_BROKER_FILE": "/run/secrets/broker", "MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_HOMEASSISTANT_URL": "http://127.0.0.1:8123", "MESH_HOMEASSISTANT_URL": "http://127.0.0.1:8123",
"MESH_HOMEASSISTANT_TOKEN_FILE": "/run/secrets/token",
"MESH_HOMEASSISTANT_CONFIG_FILE": "/run/config/config.json", "MESH_HOMEASSISTANT_CONFIG_FILE": "/run/config/config.json",
"MESH_HOMEASSISTANT_CONFIG_DIR": "/var/lib/home-assistant/config" "MESH_HOMEASSISTANT_CONFIG_DIR": "/var/lib/home-assistant/config"
}, },
+9 -1
View File
@@ -48,6 +48,14 @@ function meshConfig(file?: string): Record<string, string> {
catch { return {}; } catch { return {}; }
} }
/** Read a secret the mesh mounted at a file path (an own-secret delivered by `secret accept`);
* absent or unreadable yields undefined so callers fall back rather than crash. */
function readSecret(file?: string): string | undefined {
if (!file) return undefined;
try { return readFileSync(file, "utf8").trim(); }
catch { return undefined; }
}
export class NzbgetClient { export class NzbgetClient {
readonly rpcUrl: string; readonly rpcUrl: string;
private readonly auth: string; private readonly auth: string;
@@ -66,7 +74,7 @@ export class NzbgetClient {
static fromEnv(env: NodeJS.ProcessEnv = process.env): NzbgetClient { static fromEnv(env: NodeJS.ProcessEnv = process.env): NzbgetClient {
const cfg = meshConfig(env.MESH_NZBGET_CONFIG_FILE); const cfg = meshConfig(env.MESH_NZBGET_CONFIG_FILE);
const url = cfg.url ?? env.MESH_NZBGET_URL; const url = cfg.url ?? env.MESH_NZBGET_URL;
const password = cfg.password ?? env.MESH_NZBGET_PASSWORD; const password = cfg.password ?? readSecret(env.MESH_NZBGET_PASSWORD_FILE) ?? env.MESH_NZBGET_PASSWORD;
if (!url || !password) { if (!url || !password) {
throw new Error("NZBGet not configured — set MESH_NZBGET_URL and MESH_NZBGET_PASSWORD"); throw new Error("NZBGet not configured — set MESH_NZBGET_URL and MESH_NZBGET_PASSWORD");
} }
+4 -1
View File
@@ -10,7 +10,8 @@
], ],
"consumes": [], "consumes": [],
"own-secrets": { "own-secrets": {
"broker": "/var/lib/mesh/nzbget/broker" "broker": "/var/lib/mesh/nzbget/broker",
"password": "/var/lib/mesh/nzbget/password"
}, },
"listens": [ "listens": [
{ {
@@ -74,12 +75,14 @@
"network": "host", "network": "host",
"volumes": [ "volumes": [
"/var/lib/mesh/nzbget/broker:/run/secrets/broker:ro", "/var/lib/mesh/nzbget/broker:/run/secrets/broker:ro",
"/var/lib/mesh/nzbget/password:/run/secrets/password:ro",
"/var/lib/mesh/nzbget/config.json:/run/config/config.json:ro", "/var/lib/mesh/nzbget/config.json:/run/config/config.json:ro",
"/services/nzbget/config:/var/lib/nzbget/config:ro" "/services/nzbget/config:/var/lib/nzbget/config:ro"
], ],
"env": { "env": {
"MESH_BROKER_FILE": "/run/secrets/broker", "MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_NZBGET_URL": "http://127.0.0.1:6789", "MESH_NZBGET_URL": "http://127.0.0.1:6789",
"MESH_NZBGET_PASSWORD_FILE": "/run/secrets/password",
"MESH_NZBGET_CONFIG_FILE": "/run/config/config.json", "MESH_NZBGET_CONFIG_FILE": "/run/config/config.json",
"MESH_NZBGET_CONFIG_DIR": "/var/lib/nzbget/config" "MESH_NZBGET_CONFIG_DIR": "/var/lib/nzbget/config"
}, },
+9 -1
View File
@@ -29,6 +29,14 @@ function meshConfig(file?: string): Record<string, string> {
catch { return {}; } catch { return {}; }
} }
/** Read a secret the mesh mounted at a file path (an own-secret delivered by `secret accept`);
* absent or unreadable yields undefined so callers fall back rather than crash. */
function readSecret(file?: string): string | undefined {
if (!file) return undefined;
try { return readFileSync(file, "utf8").trim(); }
catch { return undefined; }
}
export class OmbiClient { export class OmbiClient {
readonly baseUrl: string; readonly baseUrl: string;
@@ -44,7 +52,7 @@ export class OmbiClient {
static fromEnv(env: NodeJS.ProcessEnv = process.env): OmbiClient { static fromEnv(env: NodeJS.ProcessEnv = process.env): OmbiClient {
const cfg = meshConfig(env.MESH_OMBI_CONFIG_FILE); const cfg = meshConfig(env.MESH_OMBI_CONFIG_FILE);
const url = cfg.url ?? env.MESH_OMBI_URL; const url = cfg.url ?? env.MESH_OMBI_URL;
const apiKey = cfg.apiKey ?? env.MESH_OMBI_API_KEY; const apiKey = cfg.apiKey ?? readSecret(env.MESH_OMBI_API_KEY_FILE) ?? env.MESH_OMBI_API_KEY;
if (!url) throw new Error("no Ombi URL — set MESH_OMBI_URL"); if (!url) throw new Error("no Ombi URL — set MESH_OMBI_URL");
if (!apiKey) throw new Error("no Ombi API key — set MESH_OMBI_API_KEY"); if (!apiKey) throw new Error("no Ombi API key — set MESH_OMBI_API_KEY");
return new OmbiClient(url, apiKey); return new OmbiClient(url, apiKey);
+4 -1
View File
@@ -9,7 +9,8 @@
"module.ombi.request.approved" "module.ombi.request.approved"
], ],
"own-secrets": { "own-secrets": {
"broker": "/var/lib/mesh/ombi/broker" "broker": "/var/lib/mesh/ombi/broker",
"api-key": "/var/lib/mesh/ombi/api-key"
}, },
"listens": [ "listens": [
{ {
@@ -66,12 +67,14 @@
"network": "host", "network": "host",
"volumes": [ "volumes": [
"/var/lib/mesh/ombi/broker:/run/secrets/broker:ro", "/var/lib/mesh/ombi/broker:/run/secrets/broker:ro",
"/var/lib/mesh/ombi/api-key:/run/secrets/api-key:ro",
"/var/lib/mesh/ombi/config.json:/run/config/config.json:ro", "/var/lib/mesh/ombi/config.json:/run/config/config.json:ro",
"/services/ombi/config:/var/lib/ombi/config:ro" "/services/ombi/config:/var/lib/ombi/config:ro"
], ],
"env": { "env": {
"MESH_BROKER_FILE": "/run/secrets/broker", "MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_OMBI_URL": "http://127.0.0.1:3579", "MESH_OMBI_URL": "http://127.0.0.1:3579",
"MESH_OMBI_API_KEY_FILE": "/run/secrets/api-key",
"MESH_OMBI_CONFIG_FILE": "/run/config/config.json", "MESH_OMBI_CONFIG_FILE": "/run/config/config.json",
"MESH_OMBI_CONFIG_DIR": "/var/lib/ombi/config" "MESH_OMBI_CONFIG_DIR": "/var/lib/ombi/config"
}, },
+14 -1
View File
@@ -5,6 +5,17 @@
import { existsSync, readFileSync } from "node:fs"; import { existsSync, readFileSync } from "node:fs";
import { join } from "node:path"; import { join } from "node:path";
/** Read a secret the mesh mounted at a file path (an own-secret); absent or unreadable yields
* undefined, so callers can fall back rather than crash. */
function readSecret(path: string | undefined): string | undefined {
if (!path) return undefined;
try {
return readFileSync(path, "utf8").trim();
} catch {
return undefined;
}
}
export interface PlexLibrary { export interface PlexLibrary {
key: string; key: string;
title: string; title: string;
@@ -47,7 +58,9 @@ export class PlexClient {
static fromEnv(env: NodeJS.ProcessEnv = process.env): PlexClient { static fromEnv(env: NodeJS.ProcessEnv = process.env): PlexClient {
const url = env.MESH_PLEX_URL ?? `http://127.0.0.1:${env.PLEX_PORT ?? "32400"}`; const url = env.MESH_PLEX_URL ?? `http://127.0.0.1:${env.PLEX_PORT ?? "32400"}`;
const dataDir = env.MESH_PLEX_DATA_DIR ?? "/var/lib/plex"; const dataDir = env.MESH_PLEX_DATA_DIR ?? "/var/lib/plex";
const token = env.MESH_PLEX_TOKEN ?? PlexClient.detectToken(dataDir); // The operator-provided token is an own-secret the mesh mounts at MESH_PLEX_TOKEN_FILE (delivered
// by `secret accept`); prefer it, fall back to a bare env var, then to discovery from the data dir.
const token = readSecret(env.MESH_PLEX_TOKEN_FILE) ?? env.MESH_PLEX_TOKEN ?? PlexClient.detectToken(dataDir);
if (!token) throw new Error("no Plex token — set MESH_PLEX_TOKEN or make the data dir readable"); if (!token) throw new Error("no Plex token — set MESH_PLEX_TOKEN or make the data dir readable");
return new PlexClient(url, token); return new PlexClient(url, token);
} }
+4 -1
View File
@@ -13,7 +13,8 @@
"module.*.download.completed" "module.*.download.completed"
], ],
"own-secrets": { "own-secrets": {
"broker": "/var/lib/mesh/plex/broker" "broker": "/var/lib/mesh/plex/broker",
"token": "/var/lib/mesh/plex/token"
}, },
"listens": [ "listens": [
{ {
@@ -95,11 +96,13 @@
"network": "host", "network": "host",
"volumes": [ "volumes": [
"/var/lib/mesh/plex/broker:/run/secrets/broker:ro", "/var/lib/mesh/plex/broker:/run/secrets/broker:ro",
"/var/lib/mesh/plex/token:/run/secrets/token:ro",
"/services/plex/config:/var/lib/plex/config:ro" "/services/plex/config:/var/lib/plex/config:ro"
], ],
"env": { "env": {
"MESH_BROKER_FILE": "/run/secrets/broker", "MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_PLEX_URL": "http://127.0.0.1:32400", "MESH_PLEX_URL": "http://127.0.0.1:32400",
"MESH_PLEX_TOKEN_FILE": "/run/secrets/token",
"MESH_PLEX_DATA_DIR": "/var/lib/plex" "MESH_PLEX_DATA_DIR": "/var/lib/plex"
} }
} }
+9 -1
View File
@@ -39,6 +39,14 @@ function meshConfig(file?: string): Record<string, string> {
catch { return {}; } catch { return {}; }
} }
/** Read a secret the mesh mounted at a file path (an own-secret delivered by `secret accept`);
* absent or unreadable yields undefined so callers fall back rather than crash. */
function readSecret(file?: string): string | undefined {
if (!file) return undefined;
try { return readFileSync(file, "utf8").trim(); }
catch { return undefined; }
}
export class QbittorrentClient { export class QbittorrentClient {
readonly baseUrl: string; readonly baseUrl: string;
private sid: string | null = null; private sid: string | null = null;
@@ -60,7 +68,7 @@ export class QbittorrentClient {
static fromEnv(env: NodeJS.ProcessEnv = process.env): QbittorrentClient { static fromEnv(env: NodeJS.ProcessEnv = process.env): QbittorrentClient {
const cfg = meshConfig(env.MESH_QBITTORRENT_CONFIG_FILE); const cfg = meshConfig(env.MESH_QBITTORRENT_CONFIG_FILE);
const url = cfg.url ?? env.MESH_QBITTORRENT_URL; const url = cfg.url ?? env.MESH_QBITTORRENT_URL;
const password = cfg.password ?? env.MESH_QBITTORRENT_PASSWORD; const password = cfg.password ?? readSecret(env.MESH_QBITTORRENT_PASSWORD_FILE) ?? env.MESH_QBITTORRENT_PASSWORD;
if (!url || !password) { if (!url || !password) {
throw new Error("qBittorrent not configured — set MESH_QBITTORRENT_URL and MESH_QBITTORRENT_PASSWORD"); throw new Error("qBittorrent not configured — set MESH_QBITTORRENT_URL and MESH_QBITTORRENT_PASSWORD");
} }
+4 -1
View File
@@ -10,7 +10,8 @@
], ],
"consumes": [], "consumes": [],
"own-secrets": { "own-secrets": {
"broker": "/var/lib/mesh/qbittorrent/broker" "broker": "/var/lib/mesh/qbittorrent/broker",
"password": "/var/lib/mesh/qbittorrent/password"
}, },
"listens": [ "listens": [
{ {
@@ -74,12 +75,14 @@
"network": "host", "network": "host",
"volumes": [ "volumes": [
"/var/lib/mesh/qbittorrent/broker:/run/secrets/broker:ro", "/var/lib/mesh/qbittorrent/broker:/run/secrets/broker:ro",
"/var/lib/mesh/qbittorrent/password:/run/secrets/password:ro",
"/var/lib/mesh/qbittorrent/config.json:/run/config/config.json:ro", "/var/lib/mesh/qbittorrent/config.json:/run/config/config.json:ro",
"/services/qbittorrent/config:/var/lib/qbittorrent/config:ro" "/services/qbittorrent/config:/var/lib/qbittorrent/config:ro"
], ],
"env": { "env": {
"MESH_BROKER_FILE": "/run/secrets/broker", "MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_QBITTORRENT_URL": "http://127.0.0.1:8080", "MESH_QBITTORRENT_URL": "http://127.0.0.1:8080",
"MESH_QBITTORRENT_PASSWORD_FILE": "/run/secrets/password",
"MESH_QBITTORRENT_CONFIG_FILE": "/run/config/config.json", "MESH_QBITTORRENT_CONFIG_FILE": "/run/config/config.json",
"MESH_QBITTORRENT_CONFIG_DIR": "/var/lib/qbittorrent/config" "MESH_QBITTORRENT_CONFIG_DIR": "/var/lib/qbittorrent/config"
}, },
+13 -1
View File
@@ -2,6 +2,18 @@
// changes when umami's API does (novox/hq ADR 0039). Both this module's tools and its provisioner // changes when umami's API does (novox/hq ADR 0039). Both this module's tools and its provisioner
// import it; nothing outside umami does. // import it; nothing outside umami does.
import { readFileSync } from "node:fs";
/** Read a secret from the file the mesh mounted it at, if the pointing env is set. */
function readSecret(path: string | undefined): string | undefined {
if (!path) return undefined;
try {
return readFileSync(path, "utf8").trim() || undefined;
} catch {
return undefined;
}
}
export interface Website { export interface Website {
id: string; id: string;
name: string; name: string;
@@ -23,7 +35,7 @@ export class UmamiClient {
static fromEnv(env: NodeJS.ProcessEnv = process.env): UmamiClient { static fromEnv(env: NodeJS.ProcessEnv = process.env): UmamiClient {
const url = env.MESH_PROVISION_UMAMI_URL ?? env.UMAMI_URL; const url = env.MESH_PROVISION_UMAMI_URL ?? env.UMAMI_URL;
const username = env.UMAMI_USERNAME ?? "admin"; const username = env.UMAMI_USERNAME ?? "admin";
const password = env.UMAMI_ADMIN_PASSWORD; const password = readSecret(env.MESH_UMAMI_ADMIN_PASSWORD_FILE) ?? env.UMAMI_ADMIN_PASSWORD;
if (!url || !password) { if (!url || !password) {
throw new Error("UMAMI url or admin password is not set — umami's own code cannot reach it"); throw new Error("UMAMI url or admin password is not set — umami's own code cannot reach it");
} }
+2 -1
View File
@@ -110,7 +110,8 @@
], ],
"env": { "env": {
"MESH_BROKER_FILE": "/run/secrets/broker", "MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_RECEIVES": "/var/lib/umami/grants/mesh.json" "MESH_RECEIVES": "/var/lib/umami/grants/mesh.json",
"MESH_UMAMI_ADMIN_PASSWORD_FILE": "/run/secrets/admin"
}, },
"env-file": [ "env-file": [
"/var/lib/umami/provisioner.env" "/var/lib/umami/provisioner.env"