ombi: reach plex through the mesh, in the same step as the Servarr apps
ombi reached plex at its public name, typed into its settings screen, so it depended on plex's public route and on nobody moving plex. ombi now requires plex-api, and the run-once step that writes its Servarr connections writes its Plex one too - renamed from `servarr` to `connections`, since it is no longer only that. ombi keeps several Plex servers. The entry this provision names is found by the server's own machineIdentifier (plex answers it at /identity, and ombi stored it when the server was loaded), and only its host, port, TLS, base path and token are written, only when they differ. Another server's entry, the selected libraries, whether Plex is enabled and every other choice are left alone. An ombi with no entry for the server gets one. The token is tried against plex first. Until the operator accepts the server's X-Plex-Token for this pair the mesh delivers a value it minted, which plex refuses (401, or 400 on a network it trusts); refused, nothing is written and the step fails naming the secret accept, so a working token in ombi is never replaced by a dead one. Tests import the compiled step, as keycloak's do: the step imports its sibling with the .js specifier the build needs, which type stripping does not resolve. `npm test` builds first.
This commit is contained in:
@@ -1,59 +0,0 @@
|
||||
// ombi's Servarr step — run once by the host after ombi's server starts, and run again whenever a
|
||||
// binding or pair credential it reads changes (the container's `restart-on`, novox/hq ADR 0099).
|
||||
//
|
||||
// **A step, not a loop**, for the reason route-adapter gives: everything it does is a function of
|
||||
// files the mesh writes, and the host already knows when they change. It connects to no broker.
|
||||
//
|
||||
// Exits non-zero when any app could not be put right — a refused credential, an unreachable app, an
|
||||
// ombi that cannot reach it — so the node reports the step failed and the host runs it again on the
|
||||
// next apply. It is declared last in the manifest, so its failing gates nothing else of ombi's
|
||||
// (novox/hq ADR 0136).
|
||||
//
|
||||
// Reads, per app, `<dir>/<provision>.json` (the binding) and `<dir>/<provision>.secret` (the pair
|
||||
// credential), where <dir> is MESH_SERVARR_DIR. Never prints a key.
|
||||
|
||||
import { join } from "node:path";
|
||||
|
||||
import { APPS, ombiReady, readBinding, readIfThere, reconcileApp, type Http } from "./settings.js";
|
||||
|
||||
const dir = process.env.MESH_SERVARR_DIR ?? "/run/servarr";
|
||||
const url = process.env.MESH_OMBI_URL ?? "http://127.0.0.1:3579";
|
||||
const apiKey = (await readIfThere(process.env.MESH_OMBI_API_KEY_FILE))?.trim() ?? process.env.MESH_OMBI_API_KEY ?? "";
|
||||
const waitSeconds = Number(process.env.MESH_OMBI_WAIT_SECONDS ?? "180");
|
||||
|
||||
const http: Http = { fetch: (u, init) => fetch(u, init) };
|
||||
|
||||
if (!apiKey) {
|
||||
console.error("[ombi-servarr] no ombi API key — ombi's own `api-key` secret has not been accepted");
|
||||
process.exit(1);
|
||||
}
|
||||
const ombi = { url, apiKey };
|
||||
|
||||
if (!(await ombiReady(http, ombi, waitSeconds * 1000))) {
|
||||
console.error(`[ombi-servarr] ombi did not answer at ${url} within ${waitSeconds}s`);
|
||||
process.exit(1);
|
||||
}
|
||||
|
||||
let failed = 0;
|
||||
for (const spec of APPS) {
|
||||
const outcome = await reconcileApp(
|
||||
http,
|
||||
ombi,
|
||||
spec,
|
||||
await readBinding(join(dir, `${spec.provision}.json`)),
|
||||
await readIfThere(join(dir, `${spec.provision}.secret`)),
|
||||
);
|
||||
switch (outcome.result) {
|
||||
case "unchanged":
|
||||
console.log(`[ombi-servarr] ${outcome.app}: already as the mesh says; connection tested`);
|
||||
break;
|
||||
case "written":
|
||||
console.log(`[ombi-servarr] ${outcome.app}: wrote ${outcome.fields.join(", ")}; connection tested`);
|
||||
break;
|
||||
case "refused":
|
||||
failed++;
|
||||
console.error(`[ombi-servarr] ${outcome.app}: ${outcome.problem}`);
|
||||
break;
|
||||
}
|
||||
}
|
||||
process.exitCode = failed > 0 ? 1 : 0;
|
||||
@@ -115,7 +115,7 @@ export function subDirOf(urlBase: unknown): string | null {
|
||||
return trimmed === "" ? null : trimmed;
|
||||
}
|
||||
|
||||
function isLoopback(host: string): boolean {
|
||||
export function isLoopback(host: string): boolean {
|
||||
const h = host.toLowerCase();
|
||||
return h === "localhost" || h === "::1" || h === "[::1]" || /^127\./.test(h);
|
||||
}
|
||||
@@ -163,7 +163,7 @@ export interface Ombi {
|
||||
apiKey: string;
|
||||
}
|
||||
|
||||
async function ombiCall(http: Http, ombi: Ombi, method: string, path: string, body?: unknown): Promise<unknown> {
|
||||
export async function ombiCall(http: Http, ombi: Ombi, method: string, path: string, body?: unknown): Promise<unknown> {
|
||||
const res = await http.fetch(`${ombi.url.replace(/\/$/, "")}/api/v1${path}`, {
|
||||
method,
|
||||
headers: {
|
||||
|
||||
Reference in New Issue
Block a user