modules: wire tool-runtime app credentials as own-secrets
The six modules that run a mesh-<mod> tool-runtime sidecar read an app credential from an env var the manifest never provided, so the sidecar crash-looped in the whole-mesh dry-run (e.g. "no Plex token — set MESH_PLEX_TOKEN"). These are operator-set app secrets, so deliver them the same way cloudflare-dns delivers its API token: an own-secret file mounted read-only, with a MESH_<APP>_*_FILE env pointing at the mount, and the runtime code preferring that file (falling back to the existing env so nothing regresses). - plex: own-secret token -> /run/secrets/token, MESH_PLEX_TOKEN_FILE - bazarr: own-secret api-key -> /run/secrets/api-key, MESH_BAZARR_API_KEY_FILE - ombi: own-secret api-key -> /run/secrets/api-key, MESH_OMBI_API_KEY_FILE - home-assistant: own-secret token -> /run/secrets/token, MESH_HOMEASSISTANT_TOKEN_FILE - nzbget: own-secret password -> /run/secrets/password, MESH_NZBGET_PASSWORD_FILE (URL stays plain env) - qbittorrent: own-secret password -> /run/secrets/password, MESH_QBITTORRENT_PASSWORD_FILE (URL stays plain env) The operator now completes each with `secret accept <node> <module> <name> --from <file>`. tsc passes for all six.
This commit is contained in:
@@ -43,6 +43,14 @@ function meshConfig(file?: string): Record<string, string> {
|
|||||||
catch { return {}; }
|
catch { return {}; }
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/** Read a secret the mesh mounted at a file path (an own-secret delivered by `secret accept`);
|
||||||
|
* absent or unreadable yields undefined so callers fall back rather than crash. */
|
||||||
|
function readSecret(file?: string): string | undefined {
|
||||||
|
if (!file) return undefined;
|
||||||
|
try { return readFileSync(file, "utf8").trim(); }
|
||||||
|
catch { return undefined; }
|
||||||
|
}
|
||||||
|
|
||||||
export class BazarrClient {
|
export class BazarrClient {
|
||||||
readonly baseUrl: string;
|
readonly baseUrl: string;
|
||||||
|
|
||||||
@@ -58,7 +66,7 @@ export class BazarrClient {
|
|||||||
static fromEnv(env: NodeJS.ProcessEnv = process.env): BazarrClient {
|
static fromEnv(env: NodeJS.ProcessEnv = process.env): BazarrClient {
|
||||||
const cfg = meshConfig(env.MESH_BAZARR_CONFIG_FILE);
|
const cfg = meshConfig(env.MESH_BAZARR_CONFIG_FILE);
|
||||||
const url = cfg.url ?? env.MESH_BAZARR_URL;
|
const url = cfg.url ?? env.MESH_BAZARR_URL;
|
||||||
const apiKey = cfg.apiKey ?? env.MESH_BAZARR_API_KEY;
|
const apiKey = cfg.apiKey ?? readSecret(env.MESH_BAZARR_API_KEY_FILE) ?? env.MESH_BAZARR_API_KEY;
|
||||||
if (!url) throw new Error("no Bazarr URL — set MESH_BAZARR_URL");
|
if (!url) throw new Error("no Bazarr URL — set MESH_BAZARR_URL");
|
||||||
if (!apiKey) throw new Error("no Bazarr API key — set MESH_BAZARR_API_KEY");
|
if (!apiKey) throw new Error("no Bazarr API key — set MESH_BAZARR_API_KEY");
|
||||||
return new BazarrClient(url, apiKey);
|
return new BazarrClient(url, apiKey);
|
||||||
|
|||||||
@@ -8,7 +8,8 @@
|
|||||||
"module.bazarr.subtitle.downloaded"
|
"module.bazarr.subtitle.downloaded"
|
||||||
],
|
],
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"broker": "/var/lib/mesh/bazarr/broker"
|
"broker": "/var/lib/mesh/bazarr/broker",
|
||||||
|
"api-key": "/var/lib/mesh/bazarr/api-key"
|
||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
@@ -87,12 +88,14 @@
|
|||||||
"network": "host",
|
"network": "host",
|
||||||
"volumes": [
|
"volumes": [
|
||||||
"/var/lib/mesh/bazarr/broker:/run/secrets/broker:ro",
|
"/var/lib/mesh/bazarr/broker:/run/secrets/broker:ro",
|
||||||
|
"/var/lib/mesh/bazarr/api-key:/run/secrets/api-key:ro",
|
||||||
"/var/lib/mesh/bazarr/config.json:/run/config/config.json:ro",
|
"/var/lib/mesh/bazarr/config.json:/run/config/config.json:ro",
|
||||||
"/services/bazarr/config:/var/lib/bazarr/config:ro"
|
"/services/bazarr/config:/var/lib/bazarr/config:ro"
|
||||||
],
|
],
|
||||||
"env": {
|
"env": {
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||||
"MESH_BAZARR_URL": "http://127.0.0.1:6767",
|
"MESH_BAZARR_URL": "http://127.0.0.1:6767",
|
||||||
|
"MESH_BAZARR_API_KEY_FILE": "/run/secrets/api-key",
|
||||||
"MESH_BAZARR_CONFIG_FILE": "/run/config/config.json",
|
"MESH_BAZARR_CONFIG_FILE": "/run/config/config.json",
|
||||||
"MESH_BAZARR_CONFIG_DIR": "/var/lib/bazarr/config"
|
"MESH_BAZARR_CONFIG_DIR": "/var/lib/bazarr/config"
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -27,6 +27,14 @@ function meshConfig(file?: string): Record<string, string> {
|
|||||||
catch { return {}; }
|
catch { return {}; }
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/** Read a secret the mesh mounted at a file path (an own-secret delivered by `secret accept`);
|
||||||
|
* absent or unreadable yields undefined so callers fall back rather than crash. */
|
||||||
|
function readSecret(file?: string): string | undefined {
|
||||||
|
if (!file) return undefined;
|
||||||
|
try { return readFileSync(file, "utf8").trim(); }
|
||||||
|
catch { return undefined; }
|
||||||
|
}
|
||||||
|
|
||||||
export class HomeAssistantClient {
|
export class HomeAssistantClient {
|
||||||
readonly baseUrl: string;
|
readonly baseUrl: string;
|
||||||
|
|
||||||
@@ -45,7 +53,7 @@ export class HomeAssistantClient {
|
|||||||
static fromEnv(env: NodeJS.ProcessEnv = process.env): HomeAssistantClient {
|
static fromEnv(env: NodeJS.ProcessEnv = process.env): HomeAssistantClient {
|
||||||
const cfg = meshConfig(env.MESH_HOMEASSISTANT_CONFIG_FILE);
|
const cfg = meshConfig(env.MESH_HOMEASSISTANT_CONFIG_FILE);
|
||||||
const url = cfg.url ?? env.MESH_HOMEASSISTANT_URL ?? `http://127.0.0.1:${env.HOMEASSISTANT_PORT ?? "8123"}`;
|
const url = cfg.url ?? env.MESH_HOMEASSISTANT_URL ?? `http://127.0.0.1:${env.HOMEASSISTANT_PORT ?? "8123"}`;
|
||||||
const token = cfg.token ?? env.MESH_HOMEASSISTANT_TOKEN;
|
const token = cfg.token ?? readSecret(env.MESH_HOMEASSISTANT_TOKEN_FILE) ?? env.MESH_HOMEASSISTANT_TOKEN;
|
||||||
if (!token) throw new Error("no Home Assistant token — set MESH_HOMEASSISTANT_TOKEN");
|
if (!token) throw new Error("no Home Assistant token — set MESH_HOMEASSISTANT_TOKEN");
|
||||||
return new HomeAssistantClient(url, token);
|
return new HomeAssistantClient(url, token);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -8,7 +8,8 @@
|
|||||||
"module.home-assistant.state.changed"
|
"module.home-assistant.state.changed"
|
||||||
],
|
],
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"broker": "/var/lib/mesh/home-assistant/broker"
|
"broker": "/var/lib/mesh/home-assistant/broker",
|
||||||
|
"token": "/var/lib/mesh/home-assistant/token"
|
||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
@@ -61,12 +62,14 @@
|
|||||||
"network": "host",
|
"network": "host",
|
||||||
"volumes": [
|
"volumes": [
|
||||||
"/var/lib/mesh/home-assistant/broker:/run/secrets/broker:ro",
|
"/var/lib/mesh/home-assistant/broker:/run/secrets/broker:ro",
|
||||||
|
"/var/lib/mesh/home-assistant/token:/run/secrets/token:ro",
|
||||||
"/var/lib/mesh/home-assistant/config.json:/run/config/config.json:ro",
|
"/var/lib/mesh/home-assistant/config.json:/run/config/config.json:ro",
|
||||||
"/services/home-assistant/config:/var/lib/home-assistant/config:ro"
|
"/services/home-assistant/config:/var/lib/home-assistant/config:ro"
|
||||||
],
|
],
|
||||||
"env": {
|
"env": {
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||||
"MESH_HOMEASSISTANT_URL": "http://127.0.0.1:8123",
|
"MESH_HOMEASSISTANT_URL": "http://127.0.0.1:8123",
|
||||||
|
"MESH_HOMEASSISTANT_TOKEN_FILE": "/run/secrets/token",
|
||||||
"MESH_HOMEASSISTANT_CONFIG_FILE": "/run/config/config.json",
|
"MESH_HOMEASSISTANT_CONFIG_FILE": "/run/config/config.json",
|
||||||
"MESH_HOMEASSISTANT_CONFIG_DIR": "/var/lib/home-assistant/config"
|
"MESH_HOMEASSISTANT_CONFIG_DIR": "/var/lib/home-assistant/config"
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -48,6 +48,14 @@ function meshConfig(file?: string): Record<string, string> {
|
|||||||
catch { return {}; }
|
catch { return {}; }
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/** Read a secret the mesh mounted at a file path (an own-secret delivered by `secret accept`);
|
||||||
|
* absent or unreadable yields undefined so callers fall back rather than crash. */
|
||||||
|
function readSecret(file?: string): string | undefined {
|
||||||
|
if (!file) return undefined;
|
||||||
|
try { return readFileSync(file, "utf8").trim(); }
|
||||||
|
catch { return undefined; }
|
||||||
|
}
|
||||||
|
|
||||||
export class NzbgetClient {
|
export class NzbgetClient {
|
||||||
readonly rpcUrl: string;
|
readonly rpcUrl: string;
|
||||||
private readonly auth: string;
|
private readonly auth: string;
|
||||||
@@ -66,7 +74,7 @@ export class NzbgetClient {
|
|||||||
static fromEnv(env: NodeJS.ProcessEnv = process.env): NzbgetClient {
|
static fromEnv(env: NodeJS.ProcessEnv = process.env): NzbgetClient {
|
||||||
const cfg = meshConfig(env.MESH_NZBGET_CONFIG_FILE);
|
const cfg = meshConfig(env.MESH_NZBGET_CONFIG_FILE);
|
||||||
const url = cfg.url ?? env.MESH_NZBGET_URL;
|
const url = cfg.url ?? env.MESH_NZBGET_URL;
|
||||||
const password = cfg.password ?? env.MESH_NZBGET_PASSWORD;
|
const password = cfg.password ?? readSecret(env.MESH_NZBGET_PASSWORD_FILE) ?? env.MESH_NZBGET_PASSWORD;
|
||||||
if (!url || !password) {
|
if (!url || !password) {
|
||||||
throw new Error("NZBGet not configured — set MESH_NZBGET_URL and MESH_NZBGET_PASSWORD");
|
throw new Error("NZBGet not configured — set MESH_NZBGET_URL and MESH_NZBGET_PASSWORD");
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -10,7 +10,8 @@
|
|||||||
],
|
],
|
||||||
"consumes": [],
|
"consumes": [],
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"broker": "/var/lib/mesh/nzbget/broker"
|
"broker": "/var/lib/mesh/nzbget/broker",
|
||||||
|
"password": "/var/lib/mesh/nzbget/password"
|
||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
@@ -74,12 +75,14 @@
|
|||||||
"network": "host",
|
"network": "host",
|
||||||
"volumes": [
|
"volumes": [
|
||||||
"/var/lib/mesh/nzbget/broker:/run/secrets/broker:ro",
|
"/var/lib/mesh/nzbget/broker:/run/secrets/broker:ro",
|
||||||
|
"/var/lib/mesh/nzbget/password:/run/secrets/password:ro",
|
||||||
"/var/lib/mesh/nzbget/config.json:/run/config/config.json:ro",
|
"/var/lib/mesh/nzbget/config.json:/run/config/config.json:ro",
|
||||||
"/services/nzbget/config:/var/lib/nzbget/config:ro"
|
"/services/nzbget/config:/var/lib/nzbget/config:ro"
|
||||||
],
|
],
|
||||||
"env": {
|
"env": {
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||||
"MESH_NZBGET_URL": "http://127.0.0.1:6789",
|
"MESH_NZBGET_URL": "http://127.0.0.1:6789",
|
||||||
|
"MESH_NZBGET_PASSWORD_FILE": "/run/secrets/password",
|
||||||
"MESH_NZBGET_CONFIG_FILE": "/run/config/config.json",
|
"MESH_NZBGET_CONFIG_FILE": "/run/config/config.json",
|
||||||
"MESH_NZBGET_CONFIG_DIR": "/var/lib/nzbget/config"
|
"MESH_NZBGET_CONFIG_DIR": "/var/lib/nzbget/config"
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -29,6 +29,14 @@ function meshConfig(file?: string): Record<string, string> {
|
|||||||
catch { return {}; }
|
catch { return {}; }
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/** Read a secret the mesh mounted at a file path (an own-secret delivered by `secret accept`);
|
||||||
|
* absent or unreadable yields undefined so callers fall back rather than crash. */
|
||||||
|
function readSecret(file?: string): string | undefined {
|
||||||
|
if (!file) return undefined;
|
||||||
|
try { return readFileSync(file, "utf8").trim(); }
|
||||||
|
catch { return undefined; }
|
||||||
|
}
|
||||||
|
|
||||||
export class OmbiClient {
|
export class OmbiClient {
|
||||||
readonly baseUrl: string;
|
readonly baseUrl: string;
|
||||||
|
|
||||||
@@ -44,7 +52,7 @@ export class OmbiClient {
|
|||||||
static fromEnv(env: NodeJS.ProcessEnv = process.env): OmbiClient {
|
static fromEnv(env: NodeJS.ProcessEnv = process.env): OmbiClient {
|
||||||
const cfg = meshConfig(env.MESH_OMBI_CONFIG_FILE);
|
const cfg = meshConfig(env.MESH_OMBI_CONFIG_FILE);
|
||||||
const url = cfg.url ?? env.MESH_OMBI_URL;
|
const url = cfg.url ?? env.MESH_OMBI_URL;
|
||||||
const apiKey = cfg.apiKey ?? env.MESH_OMBI_API_KEY;
|
const apiKey = cfg.apiKey ?? readSecret(env.MESH_OMBI_API_KEY_FILE) ?? env.MESH_OMBI_API_KEY;
|
||||||
if (!url) throw new Error("no Ombi URL — set MESH_OMBI_URL");
|
if (!url) throw new Error("no Ombi URL — set MESH_OMBI_URL");
|
||||||
if (!apiKey) throw new Error("no Ombi API key — set MESH_OMBI_API_KEY");
|
if (!apiKey) throw new Error("no Ombi API key — set MESH_OMBI_API_KEY");
|
||||||
return new OmbiClient(url, apiKey);
|
return new OmbiClient(url, apiKey);
|
||||||
|
|||||||
@@ -9,7 +9,8 @@
|
|||||||
"module.ombi.request.approved"
|
"module.ombi.request.approved"
|
||||||
],
|
],
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"broker": "/var/lib/mesh/ombi/broker"
|
"broker": "/var/lib/mesh/ombi/broker",
|
||||||
|
"api-key": "/var/lib/mesh/ombi/api-key"
|
||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
@@ -66,12 +67,14 @@
|
|||||||
"network": "host",
|
"network": "host",
|
||||||
"volumes": [
|
"volumes": [
|
||||||
"/var/lib/mesh/ombi/broker:/run/secrets/broker:ro",
|
"/var/lib/mesh/ombi/broker:/run/secrets/broker:ro",
|
||||||
|
"/var/lib/mesh/ombi/api-key:/run/secrets/api-key:ro",
|
||||||
"/var/lib/mesh/ombi/config.json:/run/config/config.json:ro",
|
"/var/lib/mesh/ombi/config.json:/run/config/config.json:ro",
|
||||||
"/services/ombi/config:/var/lib/ombi/config:ro"
|
"/services/ombi/config:/var/lib/ombi/config:ro"
|
||||||
],
|
],
|
||||||
"env": {
|
"env": {
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||||
"MESH_OMBI_URL": "http://127.0.0.1:3579",
|
"MESH_OMBI_URL": "http://127.0.0.1:3579",
|
||||||
|
"MESH_OMBI_API_KEY_FILE": "/run/secrets/api-key",
|
||||||
"MESH_OMBI_CONFIG_FILE": "/run/config/config.json",
|
"MESH_OMBI_CONFIG_FILE": "/run/config/config.json",
|
||||||
"MESH_OMBI_CONFIG_DIR": "/var/lib/ombi/config"
|
"MESH_OMBI_CONFIG_DIR": "/var/lib/ombi/config"
|
||||||
},
|
},
|
||||||
|
|||||||
+14
-1
@@ -5,6 +5,17 @@
|
|||||||
import { existsSync, readFileSync } from "node:fs";
|
import { existsSync, readFileSync } from "node:fs";
|
||||||
import { join } from "node:path";
|
import { join } from "node:path";
|
||||||
|
|
||||||
|
/** Read a secret the mesh mounted at a file path (an own-secret); absent or unreadable yields
|
||||||
|
* undefined, so callers can fall back rather than crash. */
|
||||||
|
function readSecret(path: string | undefined): string | undefined {
|
||||||
|
if (!path) return undefined;
|
||||||
|
try {
|
||||||
|
return readFileSync(path, "utf8").trim();
|
||||||
|
} catch {
|
||||||
|
return undefined;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
export interface PlexLibrary {
|
export interface PlexLibrary {
|
||||||
key: string;
|
key: string;
|
||||||
title: string;
|
title: string;
|
||||||
@@ -47,7 +58,9 @@ export class PlexClient {
|
|||||||
static fromEnv(env: NodeJS.ProcessEnv = process.env): PlexClient {
|
static fromEnv(env: NodeJS.ProcessEnv = process.env): PlexClient {
|
||||||
const url = env.MESH_PLEX_URL ?? `http://127.0.0.1:${env.PLEX_PORT ?? "32400"}`;
|
const url = env.MESH_PLEX_URL ?? `http://127.0.0.1:${env.PLEX_PORT ?? "32400"}`;
|
||||||
const dataDir = env.MESH_PLEX_DATA_DIR ?? "/var/lib/plex";
|
const dataDir = env.MESH_PLEX_DATA_DIR ?? "/var/lib/plex";
|
||||||
const token = env.MESH_PLEX_TOKEN ?? PlexClient.detectToken(dataDir);
|
// The operator-provided token is an own-secret the mesh mounts at MESH_PLEX_TOKEN_FILE (delivered
|
||||||
|
// by `secret accept`); prefer it, fall back to a bare env var, then to discovery from the data dir.
|
||||||
|
const token = readSecret(env.MESH_PLEX_TOKEN_FILE) ?? env.MESH_PLEX_TOKEN ?? PlexClient.detectToken(dataDir);
|
||||||
if (!token) throw new Error("no Plex token — set MESH_PLEX_TOKEN or make the data dir readable");
|
if (!token) throw new Error("no Plex token — set MESH_PLEX_TOKEN or make the data dir readable");
|
||||||
return new PlexClient(url, token);
|
return new PlexClient(url, token);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -13,7 +13,8 @@
|
|||||||
"module.*.download.completed"
|
"module.*.download.completed"
|
||||||
],
|
],
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"broker": "/var/lib/mesh/plex/broker"
|
"broker": "/var/lib/mesh/plex/broker",
|
||||||
|
"token": "/var/lib/mesh/plex/token"
|
||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
@@ -95,11 +96,13 @@
|
|||||||
"network": "host",
|
"network": "host",
|
||||||
"volumes": [
|
"volumes": [
|
||||||
"/var/lib/mesh/plex/broker:/run/secrets/broker:ro",
|
"/var/lib/mesh/plex/broker:/run/secrets/broker:ro",
|
||||||
|
"/var/lib/mesh/plex/token:/run/secrets/token:ro",
|
||||||
"/services/plex/config:/var/lib/plex/config:ro"
|
"/services/plex/config:/var/lib/plex/config:ro"
|
||||||
],
|
],
|
||||||
"env": {
|
"env": {
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||||
"MESH_PLEX_URL": "http://127.0.0.1:32400",
|
"MESH_PLEX_URL": "http://127.0.0.1:32400",
|
||||||
|
"MESH_PLEX_TOKEN_FILE": "/run/secrets/token",
|
||||||
"MESH_PLEX_DATA_DIR": "/var/lib/plex"
|
"MESH_PLEX_DATA_DIR": "/var/lib/plex"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -39,6 +39,14 @@ function meshConfig(file?: string): Record<string, string> {
|
|||||||
catch { return {}; }
|
catch { return {}; }
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/** Read a secret the mesh mounted at a file path (an own-secret delivered by `secret accept`);
|
||||||
|
* absent or unreadable yields undefined so callers fall back rather than crash. */
|
||||||
|
function readSecret(file?: string): string | undefined {
|
||||||
|
if (!file) return undefined;
|
||||||
|
try { return readFileSync(file, "utf8").trim(); }
|
||||||
|
catch { return undefined; }
|
||||||
|
}
|
||||||
|
|
||||||
export class QbittorrentClient {
|
export class QbittorrentClient {
|
||||||
readonly baseUrl: string;
|
readonly baseUrl: string;
|
||||||
private sid: string | null = null;
|
private sid: string | null = null;
|
||||||
@@ -60,7 +68,7 @@ export class QbittorrentClient {
|
|||||||
static fromEnv(env: NodeJS.ProcessEnv = process.env): QbittorrentClient {
|
static fromEnv(env: NodeJS.ProcessEnv = process.env): QbittorrentClient {
|
||||||
const cfg = meshConfig(env.MESH_QBITTORRENT_CONFIG_FILE);
|
const cfg = meshConfig(env.MESH_QBITTORRENT_CONFIG_FILE);
|
||||||
const url = cfg.url ?? env.MESH_QBITTORRENT_URL;
|
const url = cfg.url ?? env.MESH_QBITTORRENT_URL;
|
||||||
const password = cfg.password ?? env.MESH_QBITTORRENT_PASSWORD;
|
const password = cfg.password ?? readSecret(env.MESH_QBITTORRENT_PASSWORD_FILE) ?? env.MESH_QBITTORRENT_PASSWORD;
|
||||||
if (!url || !password) {
|
if (!url || !password) {
|
||||||
throw new Error("qBittorrent not configured — set MESH_QBITTORRENT_URL and MESH_QBITTORRENT_PASSWORD");
|
throw new Error("qBittorrent not configured — set MESH_QBITTORRENT_URL and MESH_QBITTORRENT_PASSWORD");
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -10,7 +10,8 @@
|
|||||||
],
|
],
|
||||||
"consumes": [],
|
"consumes": [],
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"broker": "/var/lib/mesh/qbittorrent/broker"
|
"broker": "/var/lib/mesh/qbittorrent/broker",
|
||||||
|
"password": "/var/lib/mesh/qbittorrent/password"
|
||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
@@ -74,12 +75,14 @@
|
|||||||
"network": "host",
|
"network": "host",
|
||||||
"volumes": [
|
"volumes": [
|
||||||
"/var/lib/mesh/qbittorrent/broker:/run/secrets/broker:ro",
|
"/var/lib/mesh/qbittorrent/broker:/run/secrets/broker:ro",
|
||||||
|
"/var/lib/mesh/qbittorrent/password:/run/secrets/password:ro",
|
||||||
"/var/lib/mesh/qbittorrent/config.json:/run/config/config.json:ro",
|
"/var/lib/mesh/qbittorrent/config.json:/run/config/config.json:ro",
|
||||||
"/services/qbittorrent/config:/var/lib/qbittorrent/config:ro"
|
"/services/qbittorrent/config:/var/lib/qbittorrent/config:ro"
|
||||||
],
|
],
|
||||||
"env": {
|
"env": {
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||||
"MESH_QBITTORRENT_URL": "http://127.0.0.1:8080",
|
"MESH_QBITTORRENT_URL": "http://127.0.0.1:8080",
|
||||||
|
"MESH_QBITTORRENT_PASSWORD_FILE": "/run/secrets/password",
|
||||||
"MESH_QBITTORRENT_CONFIG_FILE": "/run/config/config.json",
|
"MESH_QBITTORRENT_CONFIG_FILE": "/run/config/config.json",
|
||||||
"MESH_QBITTORRENT_CONFIG_DIR": "/var/lib/qbittorrent/config"
|
"MESH_QBITTORRENT_CONFIG_DIR": "/var/lib/qbittorrent/config"
|
||||||
},
|
},
|
||||||
|
|||||||
Reference in New Issue
Block a user