sonarr, radarr: tool runtime container + self-detect API key from config.xml (ADR 0052)

Mirrors plex: a broker-bound runtime that serves the module's tools, discovering
the app's API key from its own config.xml under a read-only config-dir mount, URL
defaulting to the server on the node. Proven in the mesh-lab: assigned-sonarr green
(key detected, tools served under the scoped account, no live Sonarr needed).

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
2026-09-04 22:54:53 +02:00
parent 6615b5e3b3
commit 7b55e834e9
4 changed files with 81 additions and 15 deletions
+25 -8
View File
@@ -3,6 +3,9 @@
// change to Sonarr's API rebuilds only sonarr and nothing else. Both this module's tools and its
// events entrypoint import it, and nothing outside sonarr does.
import { existsSync, readFileSync } from "node:fs";
import { join } from "node:path";
// Sonarr speaks the v3 API; its content is "series".
const API_VERSION = "v3";
const CONTENT_ENDPOINT = "series";
@@ -42,20 +45,34 @@ export class SonarrClient {
}
/**
* Build from the module's resolved environment. URL and key are read from MESH_SONARR_URL and
* MESH_SONARR_API_KEY; both must be present — an unconfigured Sonarr throws rather than pretend to
* be reachable, so the tools/events simply do not load (the harness treats the throw as "exposes
* nothing").
* Build from the module's resolved environment. The URL defaults to the server on this node
* (the runtime shares its network), and the API key is read from MESH_SONARR_API_KEY or, failing
* that, discovered from the server's own config.xml under MESH_SONARR_CONFIG_DIR — the same file
* Sonarr writes it to, so a running server needs nothing configured by hand (as plex does with
* its token). Throws when no key can be found, so the tools/events simply do not load (the harness
* treats the throw as "exposes nothing").
*/
static fromEnv(env: NodeJS.ProcessEnv = process.env): SonarrClient {
const url = env.MESH_SONARR_URL;
const apiKey = env.MESH_SONARR_API_KEY;
if (!url || !apiKey) {
throw new Error("Sonarr not configured — set MESH_SONARR_URL and MESH_SONARR_API_KEY");
const url = env.MESH_SONARR_URL ?? `http://127.0.0.1:${env.MESH_SONARR_PORT ?? "8989"}`;
const configDir = env.MESH_SONARR_CONFIG_DIR ?? "/config";
const apiKey = env.MESH_SONARR_API_KEY ?? SonarrClient.detectApiKey(configDir);
if (!apiKey) {
throw new Error("Sonarr not configured — set MESH_SONARR_API_KEY or make the config dir readable");
}
return new SonarrClient(url, apiKey);
}
/** Discover the API key from the server's config.xml, falling back to null. Every Servarr app
* writes <ApiKey> into config.xml at the root of its config directory. */
static detectApiKey(configDir: string): string | null {
const config = join(configDir, "config.xml");
if (existsSync(config)) {
const match = readFileSync(config, "utf8").match(/<ApiKey>([^<]+)<\/ApiKey>/);
if (match) return match[1];
}
return null;
}
private async get(endpoint: string, params?: Record<string, string>): Promise<unknown> {
const url = new URL(`${this.baseUrl}/api/${API_VERSION}/${endpoint}`);
if (params) {