The manifest named /services/plex/{config,transcode} with owner and mode.
On ace /services/plex is a link to /mnt/plex, plex's 133 GB of state, so
a take would have chmod'ed 0700 the top of the one directory the operator
ruled must never be re-moded or re-owned. The directories are now pathless
(config, data, transcode), placed by the mesh; on an adopted machine they
must be placed where the data is (hq 153) before plex is ever taken.
- The container sees exactly the paths ace's plex sees today: /config,
/data (HAL mounts it; the catalogue did not), /transcode and all eight
libraries, including sport-games, live-shows and formula-1. A library
whose mount disappears is emptied by Plex's automatic trash emptying,
taking its watch state with it.
- Libraries are mounted read-only, as the accesses already said.
- Owner 1000:1000 and mode 0755: plex runs as uid 1000 (the image reads
PLEX_UID, not the PUID HAL passes), pms-docker leaves its dirs 0755, and
ace's /mnt/plex is 1000:1000 0755 - so placing adopted data is a no-op.
- Image pinned to what ace runs, 1.43.4.10903; the old pin was 1.43.3.
- ADVERTISE_IP comes from the route's own public name through an env-file
(${bound:route:name}); it depends on mesh-controller #149, and without
it the declaration is refused, not applied.
- The server is routed (label plex) and declares its four GDM discovery
ports, which LAN players use.
- No token secret: a minted one is not a Plex token and the sidecar
preferred it. The sidecar reads PlexOnlineToken from Preferences.xml
through its read-only config mount, and dials ${port:32400}.
Verified: catalogue tests with MESH_CATALOGUE (parse, mounts); a scratch
resolution with ace's assignment on the #149 controller renders
ADVERTISE_IP=https://plex.zurag.be/, both route names and 32400/tcp +
GDM/udp open to anywhere; on main it is refused naming "name". A
throwaway pms-docker at the pinned digest on empty dirs answered
/identity, wrote customConnections from the env-file and ran as 1000;
client.ts typechecks strict and found the token in a Preferences.xml.
The six modules that run a mesh-<mod> tool-runtime sidecar read an app
credential from an env var the manifest never provided, so the sidecar
crash-looped in the whole-mesh dry-run (e.g. "no Plex token — set
MESH_PLEX_TOKEN"). These are operator-set app secrets, so deliver them the
same way cloudflare-dns delivers its API token: an own-secret file mounted
read-only, with a MESH_<APP>_*_FILE env pointing at the mount, and the
runtime code preferring that file (falling back to the existing env so
nothing regresses).
- plex: own-secret token -> /run/secrets/token, MESH_PLEX_TOKEN_FILE
- bazarr: own-secret api-key -> /run/secrets/api-key, MESH_BAZARR_API_KEY_FILE
- ombi: own-secret api-key -> /run/secrets/api-key, MESH_OMBI_API_KEY_FILE
- home-assistant: own-secret token -> /run/secrets/token, MESH_HOMEASSISTANT_TOKEN_FILE
- nzbget: own-secret password -> /run/secrets/password, MESH_NZBGET_PASSWORD_FILE (URL stays plain env)
- qbittorrent: own-secret password -> /run/secrets/password, MESH_QBITTORRENT_PASSWORD_FILE (URL stays plain env)
The operator now completes each with `secret accept <node> <module> <name> --from <file>`.
tsc passes for all six.
plex gains a broker-bound tools/events runtime container (mesh-runtime-plex)
alongside its server, and a never-throwing plex_reachable health probe. redis and
postgres subscribe to their own lifecycle events in index.ts but declared no
consumes — so the substrate never made the queue the runtime binds and it crashed
on start (404). Declare the consume, as ADR 0046 requires. Proven end-to-end in the
mesh-lab: assigned-plex and assigned-redis both green.
Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
Moves plex's API client and tools out of the shared hal sdk into the module,
so a Plex API change rebuilds only plex. Tools: status, search, sessions,
recently-added, refresh. And a real event design: it emits playback
started/stopped and item.added by watching the server, and consumes
module.*.download.completed to rescan so a downloader's fetch becomes a
visible item. Typechecks against the sdk; manifest parses with its emits/
consumes and broker own-secret.
Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF