searxng: its settings are a file the mesh writes, not the image's defaults
The module ran searxng on the image's built-in settings, which serve html
only — so the module's own search tool (format=json) was refused by the
software it fronts. And there was no way to configure it per machine: the
only file settings reach was the sidecar's.
settings.yml is now the module's one mergeable file (JSON is YAML): generic
defaults in the manifest (json format on, limiter and image proxy off,
valkey wired), and whatever differs per machine — base_url, method,
autocomplete, suspended times — set as the assignment's settings. The
secret key is filled on the machine through ${secret:secret}, so the
secrets-in-environment exception and the env file go. Directories are
placed. Image pinned to 2026.9.20, what ace runs today (the old pin was
older, 2026.9.1).
The sidecar's config.json is no longer mergeable: settings merge into every
mergeable file of a module, and the sidecar would have received searxng's
keys. It only ever read an optional url, which its env already carries.
Verified on ace: the pinned image serves html and json from a read-only,
root-owned 0600 JSON settings.yml.
This commit is contained in:
+20
-19
@@ -5,7 +5,7 @@
|
|||||||
"container-runtime"
|
"container-runtime"
|
||||||
],
|
],
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"secret": "/var/lib/searxng-module/secret.secret",
|
"secret": "/var/lib/mesh/searxng/secret",
|
||||||
"broker": "/var/lib/mesh/searxng/broker"
|
"broker": "/var/lib/mesh/searxng/broker"
|
||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
@@ -27,22 +27,14 @@
|
|||||||
{
|
{
|
||||||
"id": "state",
|
"id": "state",
|
||||||
"type": "directory",
|
"type": "directory",
|
||||||
"path": "/var/lib/searxng-module",
|
"mode": "0700",
|
||||||
"mode": "0700"
|
"place": "."
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "valkey-data",
|
"id": "valkey-data",
|
||||||
"type": "directory",
|
"type": "directory",
|
||||||
"path": "/var/lib/searxng-module/valkey-data",
|
|
||||||
"mode": "0700"
|
"mode": "0700"
|
||||||
},
|
},
|
||||||
{
|
|
||||||
"id": "server-env",
|
|
||||||
"type": "file",
|
|
||||||
"path": "/var/lib/searxng-module/server.env",
|
|
||||||
"mode": "0600",
|
|
||||||
"content": "SEARXNG_SECRET=${secret:secret}\nSEARXNG_VALKEY_URL=valkey://valkey:6379/0\n"
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
"id": "net",
|
"id": "net",
|
||||||
"type": "network",
|
"type": "network",
|
||||||
@@ -63,30 +55,39 @@
|
|||||||
"warning"
|
"warning"
|
||||||
],
|
],
|
||||||
"volumes": [
|
"volumes": [
|
||||||
"/var/lib/searxng-module/valkey-data:/data"
|
"${dir:valkey-data}:/data"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
"id": "settings",
|
||||||
|
"type": "file",
|
||||||
|
"path": "${dir:state}/settings.yml",
|
||||||
|
"mode": "0600",
|
||||||
|
"merge": "json",
|
||||||
|
"content": "{\n \"use_default_settings\": true,\n \"server\": {\n \"secret_key\": \"${secret:secret}\",\n \"base_url\": false,\n \"limiter\": false,\n \"image_proxy\": false,\n \"public_instance\": false\n },\n \"search\": {\n \"formats\": [\"html\", \"json\"]\n },\n \"valkey\": {\n \"url\": \"valkey://valkey:6379/0\"\n }\n}\n"
|
||||||
|
},
|
||||||
{
|
{
|
||||||
"id": "server",
|
"id": "server",
|
||||||
"type": "container",
|
"type": "container",
|
||||||
"name": "searxng",
|
"name": "searxng",
|
||||||
"image": "searxng/searxng@sha256:c7cc75852051bf6254afda6ed1b920dd1677d8efe4ab141bf558f02e582f4371",
|
"image": "searxng/searxng@sha256:cd8812607ab73730a0b1a0dc4990223fe1b9e383f6f35947114d0bef7f8bb441",
|
||||||
"network": "searxng",
|
"network": "searxng",
|
||||||
"env-file": [
|
|
||||||
"/var/lib/searxng-module/server.env"
|
|
||||||
],
|
|
||||||
"ports": [
|
"ports": [
|
||||||
"8080"
|
"8080"
|
||||||
],
|
],
|
||||||
"secrets-in-environment": "SEARXNG_SECRET is env-only, but settings.yml carries server.secret_key; convertible by mounting a generated settings.yml, not yet done"
|
"volumes": [
|
||||||
|
"${dir:state}/settings.yml:/etc/searxng/settings.yml:ro"
|
||||||
|
],
|
||||||
|
"restart-on": [
|
||||||
|
"settings"
|
||||||
|
]
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "runtime-config",
|
"id": "runtime-config",
|
||||||
"type": "file",
|
"type": "file",
|
||||||
"path": "/var/lib/mesh/searxng/config.json",
|
"path": "/var/lib/mesh/searxng/config.json",
|
||||||
"mode": "0600",
|
"mode": "0600",
|
||||||
"content": "{}\n",
|
"content": "{}\n"
|
||||||
"merge": "json"
|
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "runtime",
|
"id": "runtime",
|
||||||
|
|||||||
Reference in New Issue
Block a user