From 7ad1fbd5c66f14e6de18d743b5c6aa678eec7c07 Mon Sep 17 00:00:00 2001 From: jochens Date: Tue, 29 Sep 2026 22:33:38 +0200 Subject: [PATCH 1/2] searxng: its settings are a file the mesh writes, not the image's defaults MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The module ran searxng on the image's built-in settings, which serve html only — so the module's own search tool (format=json) was refused by the software it fronts. And there was no way to configure it per machine: the only file settings reach was the sidecar's. settings.yml is now the module's one mergeable file (JSON is YAML): generic defaults in the manifest (json format on, limiter and image proxy off, valkey wired), and whatever differs per machine — base_url, method, autocomplete, suspended times — set as the assignment's settings. The secret key is filled on the machine through ${secret:secret}, so the secrets-in-environment exception and the env file go. Directories are placed. Image pinned to 2026.9.20, what ace runs today (the old pin was older, 2026.9.1). The sidecar's config.json is no longer mergeable: settings merge into every mergeable file of a module, and the sidecar would have received searxng's keys. It only ever read an optional url, which its env already carries. Verified on ace: the pinned image serves html and json from a read-only, root-owned 0600 JSON settings.yml. --- modules/searxng/module.json | 39 +++++++++++++++++++------------------ 1 file changed, 20 insertions(+), 19 deletions(-) diff --git a/modules/searxng/module.json b/modules/searxng/module.json index be03aa3..6c9ae13 100644 --- a/modules/searxng/module.json +++ b/modules/searxng/module.json @@ -5,7 +5,7 @@ "container-runtime" ], "own-secrets": { - "secret": "/var/lib/searxng-module/secret.secret", + "secret": "/var/lib/mesh/searxng/secret", "broker": "/var/lib/mesh/searxng/broker" }, "listens": [ @@ -27,22 +27,14 @@ { "id": "state", "type": "directory", - "path": "/var/lib/searxng-module", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "valkey-data", "type": "directory", - "path": "/var/lib/searxng-module/valkey-data", "mode": "0700" }, - { - "id": "server-env", - "type": "file", - "path": "/var/lib/searxng-module/server.env", - "mode": "0600", - "content": "SEARXNG_SECRET=${secret:secret}\nSEARXNG_VALKEY_URL=valkey://valkey:6379/0\n" - }, { "id": "net", "type": "network", @@ -63,30 +55,39 @@ "warning" ], "volumes": [ - "/var/lib/searxng-module/valkey-data:/data" + "${dir:valkey-data}:/data" ] }, + { + "id": "settings", + "type": "file", + "path": "${dir:state}/settings.yml", + "mode": "0600", + "merge": "json", + "content": "{\n \"use_default_settings\": true,\n \"server\": {\n \"secret_key\": \"${secret:secret}\",\n \"base_url\": false,\n \"limiter\": false,\n \"image_proxy\": false,\n \"public_instance\": false\n },\n \"search\": {\n \"formats\": [\"html\", \"json\"]\n },\n \"valkey\": {\n \"url\": \"valkey://valkey:6379/0\"\n }\n}\n" + }, { "id": "server", "type": "container", "name": "searxng", - "image": "searxng/searxng@sha256:c7cc75852051bf6254afda6ed1b920dd1677d8efe4ab141bf558f02e582f4371", + "image": "searxng/searxng@sha256:cd8812607ab73730a0b1a0dc4990223fe1b9e383f6f35947114d0bef7f8bb441", "network": "searxng", - "env-file": [ - "/var/lib/searxng-module/server.env" - ], "ports": [ "8080" ], - "secrets-in-environment": "SEARXNG_SECRET is env-only, but settings.yml carries server.secret_key; convertible by mounting a generated settings.yml, not yet done" + "volumes": [ + "${dir:state}/settings.yml:/etc/searxng/settings.yml:ro" + ], + "restart-on": [ + "settings" + ] }, { "id": "runtime-config", "type": "file", "path": "/var/lib/mesh/searxng/config.json", "mode": "0600", - "content": "{}\n", - "merge": "json" + "content": "{}\n" }, { "id": "runtime", From 63a255c5cbc04156aa62b8f7ac5b2561e5bcb60c Mon Sep 17 00:00:00 2001 From: jochens Date: Tue, 29 Sep 2026 22:41:56 +0200 Subject: [PATCH 2/2] searxng: bind its route where its state now lives MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The route binding still named /var/lib/searxng-module, the directory the previous commit placed elsewhere — the host would have written it into a directory nothing declares. Same shape as gitea and nextcloud. --- modules/searxng/module.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/modules/searxng/module.json b/modules/searxng/module.json index 6c9ae13..d2b0fa0 100644 --- a/modules/searxng/module.json +++ b/modules/searxng/module.json @@ -119,7 +119,7 @@ } }, "binds": { - "route": "/var/lib/searxng-module/route.json" + "route": "${dir:state}/route.json" }, "build": { "on": [