Compare commits
42
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
0010b6bf21 | ||
|
|
b068a9d399 | ||
|
|
f14c763463 | ||
|
|
ab44ff02e1 | ||
|
|
c4c44efb1b | ||
|
|
5cc6258326 | ||
|
|
21f5301268 | ||
|
|
8064e5da8f | ||
|
|
63a255c5cb | ||
|
|
7ad1fbd5c6 | ||
|
|
67f5f4cffd | ||
|
|
8797335fbc | ||
|
|
53dc108603 | ||
|
|
ebf5ba2d4c | ||
|
|
bbac08a7d2 | ||
|
|
784a5a6514 | ||
|
|
0c31499fb0 | ||
|
|
f118344246 | ||
|
|
822df220ab | ||
|
|
9eb1265bc8 | ||
|
|
41cfc70b53 | ||
|
|
acedc5d9d9 | ||
|
|
521a8dd1e2 | ||
|
|
e145e2236c | ||
|
|
4d7e37e319 | ||
|
|
026421fd6e | ||
|
|
af89bb11ff | ||
|
|
7c18cdbd39 | ||
|
|
4fb16b2e6b | ||
|
|
c5af8635c8 | ||
|
|
87366c5f36 | ||
|
|
f8ca36aacf | ||
|
|
812355bf31 | ||
|
|
016ddb2b3a | ||
|
|
ea17bf46d2 | ||
|
|
4258f01614 | ||
|
|
4d9b4fdfa6 | ||
|
|
eff11b1d4d | ||
|
|
4ead13d4d4 | ||
|
|
3b77dde666 | ||
|
|
5ea4961980 | ||
|
|
2b8a668d06 |
@@ -14,7 +14,7 @@
|
|||||||
},
|
},
|
||||||
"route": {
|
"route": {
|
||||||
"label": "baserow",
|
"label": "baserow",
|
||||||
"port": 80
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
@@ -30,6 +30,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 80,
|
"port": 80,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -13,6 +13,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 6767,
|
"port": 6767,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
@@ -93,7 +94,7 @@
|
|||||||
],
|
],
|
||||||
"env": {
|
"env": {
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||||
"MESH_BAZARR_URL": "http://127.0.0.1:6767",
|
"MESH_BAZARR_URL": "http://127.0.0.1:${port:6767}",
|
||||||
"MESH_BAZARR_API_KEY_FILE": "/run/secrets/api-key",
|
"MESH_BAZARR_API_KEY_FILE": "/run/secrets/api-key",
|
||||||
"MESH_BAZARR_CONFIG_FILE": "/run/config/config.json",
|
"MESH_BAZARR_CONFIG_FILE": "/run/config/config.json",
|
||||||
"MESH_BAZARR_CONFIG_DIR": "/var/lib/bazarr/config"
|
"MESH_BAZARR_CONFIG_DIR": "/var/lib/bazarr/config"
|
||||||
@@ -110,7 +111,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "subs",
|
"label": "subs",
|
||||||
"port": 6767
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
|
|||||||
@@ -15,6 +15,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 8787,
|
"port": 8787,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
@@ -75,7 +76,7 @@
|
|||||||
],
|
],
|
||||||
"env": {
|
"env": {
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||||
"MESH_BOOKSHELF_URL": "http://127.0.0.1:8787",
|
"MESH_BOOKSHELF_URL": "http://127.0.0.1:${port:8787}",
|
||||||
"MESH_BOOKSHELF_CONFIG_DIR": "/var/lib/bookshelf/config"
|
"MESH_BOOKSHELF_CONFIG_DIR": "/var/lib/bookshelf/config"
|
||||||
},
|
},
|
||||||
"artifact": "runtime"
|
"artifact": "runtime"
|
||||||
@@ -87,7 +88,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "books",
|
"label": "books",
|
||||||
"port": 8787
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
|
|||||||
@@ -0,0 +1,56 @@
|
|||||||
|
{
|
||||||
|
"module": "ca-trust",
|
||||||
|
"version": "1",
|
||||||
|
"slug": "catrust",
|
||||||
|
"capabilities": [
|
||||||
|
"service-manager"
|
||||||
|
],
|
||||||
|
"requires": [
|
||||||
|
"internal-acme-ca"
|
||||||
|
],
|
||||||
|
"seats": [
|
||||||
|
{
|
||||||
|
"name": "the-mesh-trust-anchor",
|
||||||
|
"scope": "node"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"claims": [
|
||||||
|
{
|
||||||
|
"name": "the-mesh-trust-anchor",
|
||||||
|
"scope": "node"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"resources": [
|
||||||
|
{
|
||||||
|
"id": "state",
|
||||||
|
"type": "directory",
|
||||||
|
"mode": "0700",
|
||||||
|
"place": "."
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "anchor",
|
||||||
|
"type": "file",
|
||||||
|
"path": "${dir:state}/anchor",
|
||||||
|
"mode": "0755",
|
||||||
|
"content": "#!/bin/sh\n# The mesh's internal certificate authority, trusted by this machine.\n#\n# Written by the mesh from the ca-trust module's manifest (novox/hq ADR 0147).\n# Editing it here lasts until the next apply.\n#\n# There is no prior trust to verify the fetch against \u2014 this is the thing that\n# establishes it \u2014 so it is made over the mesh's own private network, which is\n# what authenticates it (novox/hq ADR 0098, the same reasoning that lets the\n# route proxy fetch this root for itself). What comes back is checked here: a\n# body that is not a certificate is refused now, rather than believed and then\n# failed by whatever reads the trust store next.\nset -eu\n\nROOTS='https://${bound:internal-acme-ca:at}:${bound:internal-acme-ca:port}${bound:internal-acme-ca:roots}'\nANCHORS=/etc/ca-certificates/trust-source/anchors\nANCHOR=\"$ANCHORS/mesh-internal-ca.crt\"\n\n# Arch's layout, said out loud rather than assumed: a machine that keeps its\n# anchors elsewhere fails here, visibly, instead of writing a file nothing\n# reads. That failure is the signal that this belongs in the host, where one\n# operating system's difference lives (novox/hq ADR 0147, option 2).\n[ -d \"$ANCHORS\" ] || {\n\techo \"this machine keeps no trust anchors in $ANCHORS; ca-trust is written for that layout\" >&2\n\texit 1\n}\n\ncase \"${1:-}\" in\ninstall)\n\ttmp=$(mktemp)\n\ttrap 'rm -f \"$tmp\"' EXIT\n\t# The authority may still be starting, or this machine may have come up\n\t# before it: two minutes of asking, then an honest failure.\n\tn=0\n\twhile [ \"$n\" -lt 60 ]; do\n\t\tif curl --fail --silent --show-error --insecure --max-time 10 \\\n\t\t\t--output \"$tmp\" \"$ROOTS\" &&\n\t\t\tgrep -q 'BEGIN CERTIFICATE' \"$tmp\"; then\n\t\t\tinstall -m 0644 \"$tmp\" \"$ANCHOR\"\n\t\t\tupdate-ca-trust\n\t\t\texit 0\n\t\tfi\n\t\tn=$((n + 1))\n\t\tsleep 2\n\tdone\n\techo \"the authority at $ROOTS did not serve a certificate within two minutes\" >&2\n\texit 1\n\t;;\nremove)\n\t# What stopping the unit does, and therefore what being unassigned does.\n\trm -f \"$ANCHOR\"\n\tupdate-ca-trust\n\t;;\n*)\n\techo \"usage: $(basename \"$0\") install|remove\" >&2\n\texit 2\n\t;;\nesac\n"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "unit",
|
||||||
|
"type": "file",
|
||||||
|
"path": "/etc/systemd/system/mesh-ca-trust.service",
|
||||||
|
"mode": "0644",
|
||||||
|
"content": "[Unit]\nDescription=The mesh's internal certificate authority, trusted by this machine\n# novox/hq ADR 0147. Starting this unit places the mesh's root among this\n# machine's trust anchors; stopping it takes the root away again, which is what\n# the host does when the module is no longer assigned here.\nWants=network-online.target\nAfter=network-online.target\n\n[Service]\nType=oneshot\nRemainAfterExit=yes\nExecStart=${dir:state}/anchor install\nExecStop=${dir:state}/anchor remove\n\n[Install]\nWantedBy=multi-user.target\n"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "trust",
|
||||||
|
"type": "service",
|
||||||
|
"unit": "mesh-ca-trust.service",
|
||||||
|
"state": "running",
|
||||||
|
"boot": "enabled",
|
||||||
|
"restart-on": [
|
||||||
|
"anchor",
|
||||||
|
"unit"
|
||||||
|
]
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -11,7 +11,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "de-spiegel",
|
"label": "de-spiegel",
|
||||||
"port": 35621
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
@@ -23,6 +23,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 35621,
|
"port": 35621,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -29,6 +29,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "registry",
|
||||||
"port": 5000,
|
"port": 5000,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -22,11 +22,20 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "dns-udp",
|
||||||
"port": 53,
|
"port": 53,
|
||||||
"protocol": "udp",
|
"protocol": "udp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "every name for this machine and what it runs \u2014 the mesh's own answered here, the rest forwarded",
|
"why": "every name for this machine and what it runs \u2014 the mesh's own answered here, the rest forwarded",
|
||||||
"fixed": true
|
"fixed": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "dns-tcp",
|
||||||
|
"port": 53,
|
||||||
|
"protocol": "tcp",
|
||||||
|
"from": "mesh",
|
||||||
|
"why": "the same names over tcp, which a resolver answers on as well and is asked for whenever an answer will not fit in a datagram. Declared because the daemon serves it: a declaration that covers one of the two protocols its own service listens on leaves the other closed while everything reports success",
|
||||||
|
"fixed": true
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"resources": [
|
"resources": [
|
||||||
|
|||||||
@@ -33,7 +33,7 @@
|
|||||||
"type": "file",
|
"type": "file",
|
||||||
"path": "/etc/fail2ban/jail.local",
|
"path": "/etc/fail2ban/jail.local",
|
||||||
"mode": "0644",
|
"mode": "0644",
|
||||||
"content": "[INCLUDES]\n\nbefore = paths-arch.conf\n\n[DEFAULT]\n\n# Never act on the machine itself or on a tunnel peer: the mesh's private range is\n# ${machine:mesh-range}, named here rather than written as a value the module cannot\n# know (novox/hq ADR 0112). Without this, fail2ban could ban the mesh's own nodes.\nignoreip = 127.0.0.1/8 ::1 ${machine:mesh-range}\n\nbantime = 10m\nfindtime = 10m\nmaxretry = 5\n\nbanaction = ufw\nbanaction_allports = iptables-allports\n\n[sshd]\nenabled = true\nport = ssh\nlogpath = %(sshd_log)s\nbackend = %(sshd_backend)s\n"
|
"content": "[INCLUDES]\n\nbefore = paths-arch.conf\n\n[DEFAULT]\n\n# Never act on the machine itself or on a tunnel peer: the mesh's private range is\n# ${machine:mesh-range}, named here rather than written as a value the module cannot\n# know (novox/hq ADR 0112). Without this, fail2ban could ban the mesh's own nodes.\nignoreip = 127.0.0.1/8 ::1 ${machine:mesh-range}\n\nbantime = 10m\nfindtime = 10m\nmaxretry = 5\n\n# Ban through iptables, not through a firewall front-end the machine may not have. ufw is\n# installed on two of this mesh's machines and absent on the other two, and fail2ban finds out\n# only at ban time: the service reports healthy, the jail counts the attempt, the ban command\n# exits 127, and nothing is blocked. Proven on 2026-09-28 -- 'ufw: command not found' on a\n# machine the mesh reported as protected.\n#\n# The action below is this module's own, already used by the recidive jail on every machine\n# here, and it bans in DOCKER-USER as well as INPUT, so a container's published port is\n# covered too.\nbanaction = iptables-allports-dualchain\nbanaction_allports = iptables-allports-dualchain\n\n[sshd]\nenabled = true\nport = ssh\nlogpath = %(sshd_log)s\nbackend = %(sshd_backend)s\n"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "jail-sshd",
|
"id": "jail-sshd",
|
||||||
@@ -42,6 +42,14 @@
|
|||||||
"mode": "0644",
|
"mode": "0644",
|
||||||
"content": "[sshd]\nenabled = true\nport = ssh\nlogpath = %(sshd_log)s\nbackend = %(sshd_backend)s\nmaxretry = 5\n"
|
"content": "[sshd]\nenabled = true\nport = ssh\nlogpath = %(sshd_log)s\nbackend = %(sshd_backend)s\nmaxretry = 5\n"
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
"id": "log",
|
||||||
|
"type": "file",
|
||||||
|
"path": "/var/log/fail2ban.log",
|
||||||
|
"mode": "0640",
|
||||||
|
"create-once": true,
|
||||||
|
"content": ""
|
||||||
|
},
|
||||||
{
|
{
|
||||||
"id": "jail-recidive",
|
"id": "jail-recidive",
|
||||||
"type": "file",
|
"type": "file",
|
||||||
|
|||||||
@@ -229,6 +229,17 @@ export class GiteaClient {
|
|||||||
return GiteaClient.mapPull(await this.request<any>(`/repos/${owner}/${repo}/pulls/${index}`));
|
return GiteaClient.mapPull(await this.request<any>(`/repos/${owner}/${repo}/pulls/${index}`));
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/** The files a merged pull request changed, as paths from the repository's root.
|
||||||
|
*
|
||||||
|
* `limit` is what is asked for, and a merge that changed more says so rather than being read
|
||||||
|
* page by page: what the mesh does with a partial list is treat the whole repository as changed,
|
||||||
|
* so more pages would buy nothing. */
|
||||||
|
async listPullFiles(owner: string, repo: string, index: number, limit = 100): Promise<{ paths: string[]; truncated: boolean }> {
|
||||||
|
const files = await this.request<any[]>(`/repos/${owner}/${repo}/pulls/${index}/files?limit=${limit}`);
|
||||||
|
const paths = (files ?? []).map((f) => String(f?.filename ?? "")).filter((p) => p !== "");
|
||||||
|
return { paths, truncated: paths.length >= limit };
|
||||||
|
}
|
||||||
|
|
||||||
async createPullRequest(
|
async createPullRequest(
|
||||||
owner: string,
|
owner: string,
|
||||||
repo: string,
|
repo: string,
|
||||||
|
|||||||
+21
-3
@@ -61,9 +61,17 @@ import { join } from "node:path";
|
|||||||
const mergedRecord = process.env.MESH_GITEA_STATE_DIR ? join(process.env.MESH_GITEA_STATE_DIR, "merged-announced.json") : null;
|
const mergedRecord = process.env.MESH_GITEA_STATE_DIR ? join(process.env.MESH_GITEA_STATE_DIR, "merged-announced.json") : null;
|
||||||
const announced = new Set<string>();
|
const announced = new Set<string>();
|
||||||
let primedMerges = false;
|
let primedMerges = false;
|
||||||
|
// since is the moment the watching began: a merge made before it is history, whatever page of the
|
||||||
|
// forge's listing it surfaces on. Without it, an old merge past the first page — pushed into view
|
||||||
|
// as newer pull requests were updated — was announced as if it had just happened, and the mesh
|
||||||
|
// rebuilt everything built from that repository, once per old merge (2026-09-28).
|
||||||
|
let since = "";
|
||||||
if (mergedRecord && existsSync(mergedRecord)) {
|
if (mergedRecord && existsSync(mergedRecord)) {
|
||||||
try {
|
try {
|
||||||
for (const sha of JSON.parse(readFileSync(mergedRecord, "utf8")) as string[]) announced.add(sha);
|
const kept = JSON.parse(readFileSync(mergedRecord, "utf8")) as string[] | { announced: string[]; since: string };
|
||||||
|
const list = Array.isArray(kept) ? kept : kept.announced;
|
||||||
|
for (const sha of list) announced.add(sha);
|
||||||
|
since = Array.isArray(kept) ? new Date().toISOString() : kept.since;
|
||||||
primedMerges = true;
|
primedMerges = true;
|
||||||
} catch {
|
} catch {
|
||||||
// An unreadable record is treated as no record: prime again rather than re-announce history.
|
// An unreadable record is treated as no record: prime again rather than re-announce history.
|
||||||
@@ -73,7 +81,7 @@ function keepAnnounced(): void {
|
|||||||
if (!mergedRecord) return;
|
if (!mergedRecord) return;
|
||||||
mkdirSync(join(mergedRecord, ".."), { recursive: true });
|
mkdirSync(join(mergedRecord, ".."), { recursive: true });
|
||||||
const tmp = mergedRecord + ".tmp";
|
const tmp = mergedRecord + ".tmp";
|
||||||
writeFileSync(tmp, JSON.stringify([...announced].slice(-2000)));
|
writeFileSync(tmp, JSON.stringify({ announced: [...announced].slice(-2000), since }));
|
||||||
renameSync(tmp, mergedRecord);
|
renameSync(tmp, mergedRecord);
|
||||||
}
|
}
|
||||||
async function pollMerged(client: GiteaClient): Promise<void> {
|
async function pollMerged(client: GiteaClient): Promise<void> {
|
||||||
@@ -83,7 +91,14 @@ async function pollMerged(client: GiteaClient): Promise<void> {
|
|||||||
const pulls = await client.listPullRequests(repo.owner, repo.name, { state: "closed", sort: "recentupdate", limit: "20" });
|
const pulls = await client.listPullRequests(repo.owner, repo.name, { state: "closed", sort: "recentupdate", limit: "20" });
|
||||||
for (const pull of pulls) {
|
for (const pull of pulls) {
|
||||||
if (!pull.merged || !pull.merge_commit_sha || announced.has(pull.merge_commit_sha)) continue;
|
if (!pull.merged || !pull.merge_commit_sha || announced.has(pull.merge_commit_sha)) continue;
|
||||||
if (primedMerges) {
|
// Announced only if merged since the watching began; recorded either way, so it is looked
|
||||||
|
// at once.
|
||||||
|
const fresh = !!pull.merged_at && !!since && pull.merged_at > since;
|
||||||
|
if (primedMerges && fresh) {
|
||||||
|
// What it changed, asked for only now: a module is rebuilt because a file inside its own
|
||||||
|
// directory moved, and without this every module built from a repository is rebuilt for a
|
||||||
|
// change to any of them (novox/hq 04-ISSUES/131).
|
||||||
|
const changed = await client.listPullFiles(repo.owner, repo.name, pull.number);
|
||||||
await emit("pull.merged", {
|
await emit("pull.merged", {
|
||||||
owner: repo.owner,
|
owner: repo.owner,
|
||||||
repo: repo.name,
|
repo: repo.name,
|
||||||
@@ -95,6 +110,8 @@ async function pollMerged(client: GiteaClient): Promise<void> {
|
|||||||
merged_at: pull.merged_at,
|
merged_at: pull.merged_at,
|
||||||
clone_url: repo.clone_url,
|
clone_url: repo.clone_url,
|
||||||
html_url: pull.html_url,
|
html_url: pull.html_url,
|
||||||
|
paths: changed.paths,
|
||||||
|
paths_truncated: changed.truncated,
|
||||||
});
|
});
|
||||||
// Said, because a trigger that fires silently is indistinguishable from one that did not
|
// Said, because a trigger that fires silently is indistinguishable from one that did not
|
||||||
// fire (novox/hq 04-ISSUES/131) — this line is how an operator knows the mesh was told.
|
// fire (novox/hq 04-ISSUES/131) — this line is how an operator knows the mesh was told.
|
||||||
@@ -104,6 +121,7 @@ async function pollMerged(client: GiteaClient): Promise<void> {
|
|||||||
changed = true;
|
changed = true;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
if (!primedMerges) since = new Date().toISOString();
|
||||||
if (!primedMerges || changed) keepAnnounced();
|
if (!primedMerges || changed) keepAnnounced();
|
||||||
primedMerges = true;
|
primedMerges = true;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -13,7 +13,7 @@
|
|||||||
"route": {
|
"route": {
|
||||||
"web": {
|
"web": {
|
||||||
"label": "git",
|
"label": "git",
|
||||||
"port": 3000
|
"endpoint": "web"
|
||||||
},
|
},
|
||||||
"internal-api-refused": {
|
"internal-api-refused": {
|
||||||
"label": "git",
|
"label": "git",
|
||||||
@@ -44,12 +44,14 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 3000,
|
"port": 3000,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "the forge, over http"
|
"why": "the forge, over http"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "ssh",
|
||||||
"port": 22,
|
"port": 22,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -233,6 +233,9 @@ export function getGiteaTools(gitea: GiteaClient): ToolDefinition[] {
|
|||||||
await gitea.mergePullRequest(owner, repo, number, method, deleteBranch);
|
await gitea.mergePullRequest(owner, repo, number, method, deleteBranch);
|
||||||
// Read it again: the merge commit only exists now, and it is what a build is made from.
|
// Read it again: the merge commit only exists now, and it is what a build is made from.
|
||||||
const merged = await gitea.getPullRequest(owner, repo, number);
|
const merged = await gitea.getPullRequest(owner, repo, number);
|
||||||
|
// And what it changed, so the mesh rebuilds the modules whose own files moved rather than
|
||||||
|
// every module built from the repository (novox/hq 04-ISSUES/131).
|
||||||
|
const changed = await gitea.listPullFiles(owner, repo, number);
|
||||||
await emit("pull.merged", {
|
await emit("pull.merged", {
|
||||||
owner,
|
owner,
|
||||||
repo,
|
repo,
|
||||||
@@ -244,6 +247,8 @@ export function getGiteaTools(gitea: GiteaClient): ToolDefinition[] {
|
|||||||
merged_at: merged.merged_at,
|
merged_at: merged.merged_at,
|
||||||
method,
|
method,
|
||||||
html_url: pull.html_url,
|
html_url: pull.html_url,
|
||||||
|
paths: changed.paths,
|
||||||
|
paths_truncated: changed.truncated,
|
||||||
});
|
});
|
||||||
return { merged: true, number, method, deleted_branch: deleteBranch };
|
return { merged: true, number, method, deleted_branch: deleteBranch };
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -13,6 +13,7 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 3000,
|
"port": 3000,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
@@ -96,7 +97,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "grafana",
|
"label": "grafana",
|
||||||
"port": 3000
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
|
|||||||
@@ -11,7 +11,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "hello",
|
"label": "hello",
|
||||||
"port": 8080
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
@@ -19,6 +19,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 8080,
|
"port": 8080,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -14,6 +14,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 8123,
|
"port": 8123,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
@@ -85,7 +86,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "home-assistant",
|
"label": "home-assistant",
|
||||||
"port": 8123
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
|
|||||||
@@ -13,6 +13,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "stream",
|
||||||
"port": 8000,
|
"port": 8000,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -9,6 +9,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "api",
|
||||||
"port": 8086,
|
"port": 8086,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -17,11 +17,11 @@
|
|||||||
"route": {
|
"route": {
|
||||||
"site": {
|
"site": {
|
||||||
"label": "invoicing",
|
"label": "invoicing",
|
||||||
"port": 80
|
"endpoint": "web"
|
||||||
},
|
},
|
||||||
"api": {
|
"api": {
|
||||||
"label": "invoicing-api",
|
"label": "invoicing-api",
|
||||||
"port": 9000
|
"endpoint": "api"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
@@ -36,12 +36,14 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 80,
|
"port": 80,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "the invoicing web frontend; a public name is a route grant later"
|
"why": "the invoicing web frontend; a public name is a route grant later"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "api",
|
||||||
"port": 9000,
|
"port": 9000,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -6,6 +6,7 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 9117,
|
"port": 9117,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
@@ -82,7 +83,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "indexers",
|
"label": "indexers",
|
||||||
"port": 9117
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
|
|||||||
@@ -11,7 +11,7 @@
|
|||||||
},
|
},
|
||||||
"route": {
|
"route": {
|
||||||
"label": "keycloak",
|
"label": "keycloak",
|
||||||
"port": 8080
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
@@ -34,6 +34,7 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 8080,
|
"port": 8080,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -24,6 +24,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 8283,
|
"port": 8283,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -1,6 +1,19 @@
|
|||||||
{
|
{
|
||||||
"module": "lidarr",
|
"module": "lidarr",
|
||||||
"version": "1",
|
"version": "1",
|
||||||
|
"provides": [
|
||||||
|
{
|
||||||
|
"name": "lidarr-api",
|
||||||
|
"scope": "mesh"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"serves": {
|
||||||
|
"lidarr-api": {
|
||||||
|
"scheme": "http",
|
||||||
|
"port": 8686,
|
||||||
|
"url-base": ""
|
||||||
|
}
|
||||||
|
},
|
||||||
"capabilities": [
|
"capabilities": [
|
||||||
"container-runtime"
|
"container-runtime"
|
||||||
],
|
],
|
||||||
@@ -14,6 +27,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 8686,
|
"port": 8686,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
@@ -74,7 +88,7 @@
|
|||||||
],
|
],
|
||||||
"env": {
|
"env": {
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||||
"MESH_LIDARR_URL": "http://127.0.0.1:8686",
|
"MESH_LIDARR_URL": "http://127.0.0.1:${port:8686}",
|
||||||
"MESH_LIDARR_CONFIG_DIR": "/var/lib/lidarr/config"
|
"MESH_LIDARR_CONFIG_DIR": "/var/lib/lidarr/config"
|
||||||
},
|
},
|
||||||
"artifact": "runtime"
|
"artifact": "runtime"
|
||||||
@@ -86,7 +100,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "lidarr",
|
"label": "lidarr",
|
||||||
"port": 8686
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
|
|||||||
@@ -16,27 +16,27 @@
|
|||||||
"route": {
|
"route": {
|
||||||
"web": {
|
"web": {
|
||||||
"label": "mail",
|
"label": "mail",
|
||||||
"port": 7443,
|
"endpoint": "web-tls",
|
||||||
"scheme": "https",
|
"scheme": "https",
|
||||||
"insecure": true
|
"insecure": true
|
||||||
},
|
},
|
||||||
"acme": {
|
"acme": {
|
||||||
"label": "mail",
|
"label": "mail",
|
||||||
"path": "/.well-known/acme-challenge",
|
"path": "/.well-known/acme-challenge",
|
||||||
"port": 7080,
|
"endpoint": "web",
|
||||||
"priority": 100
|
"priority": 100
|
||||||
},
|
},
|
||||||
"autoconfig": {
|
"autoconfig": {
|
||||||
"label": "autoconfig",
|
"label": "autoconfig",
|
||||||
"port": 4243
|
"endpoint": "autoconfig"
|
||||||
},
|
},
|
||||||
"autodiscover": {
|
"autodiscover": {
|
||||||
"label": "autodiscover",
|
"label": "autodiscover",
|
||||||
"port": 4243
|
"endpoint": "autoconfig"
|
||||||
},
|
},
|
||||||
"automx": {
|
"automx": {
|
||||||
"label": "automx",
|
"label": "automx",
|
||||||
"port": 4243
|
"endpoint": "autoconfig"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
@@ -60,6 +60,7 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "smtp",
|
||||||
"port": 25,
|
"port": 25,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "anywhere",
|
"from": "anywhere",
|
||||||
@@ -67,6 +68,7 @@
|
|||||||
"fixed": true
|
"fixed": true
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "pop3",
|
||||||
"port": 110,
|
"port": 110,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "anywhere",
|
"from": "anywhere",
|
||||||
@@ -74,6 +76,7 @@
|
|||||||
"fixed": true
|
"fixed": true
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "imap",
|
||||||
"port": 143,
|
"port": 143,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "anywhere",
|
"from": "anywhere",
|
||||||
@@ -81,6 +84,7 @@
|
|||||||
"fixed": true
|
"fixed": true
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "smtps",
|
||||||
"port": 465,
|
"port": 465,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "anywhere",
|
"from": "anywhere",
|
||||||
@@ -88,6 +92,7 @@
|
|||||||
"fixed": true
|
"fixed": true
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "submission",
|
||||||
"port": 587,
|
"port": 587,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "anywhere",
|
"from": "anywhere",
|
||||||
@@ -95,6 +100,7 @@
|
|||||||
"fixed": true
|
"fixed": true
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "imaps",
|
||||||
"port": 993,
|
"port": 993,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "anywhere",
|
"from": "anywhere",
|
||||||
@@ -102,6 +108,7 @@
|
|||||||
"fixed": true
|
"fixed": true
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "pop3s",
|
||||||
"port": 995,
|
"port": 995,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "anywhere",
|
"from": "anywhere",
|
||||||
@@ -109,18 +116,21 @@
|
|||||||
"fixed": true
|
"fixed": true
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 7080,
|
"port": 7080,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "the web front over http; only the ACME HTTP-01 passthrough is routed here \u2014 everything else 301s to https and would loop a proxy"
|
"why": "the web front over http; only the ACME HTTP-01 passthrough is routed here \u2014 everything else 301s to https and would loop a proxy"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "web-tls",
|
||||||
"port": 7443,
|
"port": 7443,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "the web front over its own TLS (admin, webmail, API); the public name mail.novox.be is a route grant reaching it here"
|
"why": "the web front over its own TLS (admin, webmail, API); the public name mail.novox.be is a route grant reaching it here"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "autoconfig",
|
||||||
"port": 4243,
|
"port": 4243,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -6,6 +6,7 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "api",
|
||||||
"port": 59125,
|
"port": 59125,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ COPY . .
|
|||||||
# The compiler is invoked by its real path rather than through node_modules/.bin, whose entries are
|
# The compiler is invoked by its real path rather than through node_modules/.bin, whose entries are
|
||||||
# symlinks to a launcher that requires its library relatively — resolved away when the base image
|
# symlinks to a launcher that requires its library relatively — resolved away when the base image
|
||||||
# was assembled.
|
# was assembled.
|
||||||
RUN node /app/node_modules/typescript/bin/tsc pg.d.ts store.ts index.ts tools/index.ts \
|
RUN node /app/node_modules/typescript/bin/tsc pg.d.ts store.ts index.ts tools/index.ts prepare/index.ts \
|
||||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
||||||
|
|
||||||
# **A module may need something the base image does not carry.** The base holds what every module
|
# **A module may need something the base image does not carry.** The base holds what every module
|
||||||
@@ -48,3 +48,8 @@ COPY --from=build /deps/node_modules /app/modules/mesh-catalog/node_modules
|
|||||||
# to listen for what the builder announces. Serve binds the broker first, then imports these, so
|
# to listen for what the builder announces. Serve binds the broker first, then imports these, so
|
||||||
# `on()` has something to subscribe to.
|
# `on()` has something to subscribe to.
|
||||||
ENV MESH_TOOL_MODULES=/app/modules/mesh-catalog/dist/index.js,/app/modules/mesh-catalog/dist/tools/index.js
|
ENV MESH_TOOL_MODULES=/app/modules/mesh-catalog/dist/index.js,/app/modules/mesh-catalog/dist/tools/index.js
|
||||||
|
|
||||||
|
# And what prepares this module's state, for the runtime's `prepare` mode (novox/hq ADR 0135). Named
|
||||||
|
# here, beside the entrypoints above, because the module knows which of its files prepares its state
|
||||||
|
# and nothing else could: the mesh asks one word and this says what answers it.
|
||||||
|
ENV MESH_PREPARE=/app/modules/mesh-catalog/dist/prepare/index.js
|
||||||
|
|||||||
@@ -14,10 +14,12 @@ import { Graph, type Made } from "./store.js";
|
|||||||
|
|
||||||
const graph = Graph.fromEnv();
|
const graph = Graph.fromEnv();
|
||||||
|
|
||||||
// Before subscribing, and idempotent. The runtime is restarted until its store is reachable, which
|
// The schema is not brought up here. The mesh prepares this module's state before it starts this
|
||||||
// is the same arrangement model-usage uses: a schema step that had to reach the provider over the
|
// version, and does not start it if that failed (novox/hq ADR 0135) — see prepare/index.ts. Doing it
|
||||||
// overlay would block the very apply that brings the overlay up.
|
// at start made a schema that could not be reached a crash loop instead of a stop, with the graph
|
||||||
await graph.migrate();
|
// keeping a gap and nothing saying so. The reason it used to be here — that a step blocking the apply
|
||||||
|
// would block the very apply that brings the overlay up — stopped being true when a step's failure
|
||||||
|
// became this module's business and not the machine's (ADR 0136).
|
||||||
|
|
||||||
/** What the builder says when it has built something. */
|
/** What the builder says when it has built something. */
|
||||||
interface Built {
|
interface Built {
|
||||||
@@ -47,7 +49,15 @@ interface Built {
|
|||||||
replay?: boolean;
|
replay?: boolean;
|
||||||
}
|
}
|
||||||
|
|
||||||
await on("mesh-build-machine.built", async (event) => {
|
/**
|
||||||
|
* What a build means for the graph, wherever it came from.
|
||||||
|
*
|
||||||
|
* Two emitters say the same thing and neither is a mistake: the build machine says it as it happens,
|
||||||
|
* and the control plane says what it already held when this module asks what it missed
|
||||||
|
* (novox/hq ADR 0134). A replay is marked as one in its body, so nothing acts on a module that moved
|
||||||
|
* months ago — see `replay` above.
|
||||||
|
*/
|
||||||
|
const placeTheBuild = async (event: { body: unknown }): Promise<void> => {
|
||||||
const body = event.body as Built;
|
const body = event.body as Built;
|
||||||
if (!body.module || !body.commit) {
|
if (!body.module || !body.commit) {
|
||||||
// Said rather than dropped: a build that announced itself without saying what it built is a
|
// Said rather than dropped: a build that announced itself without saying what it built is a
|
||||||
@@ -89,7 +99,11 @@ await on("mesh-build-machine.built", async (event) => {
|
|||||||
because: next.because,
|
because: next.because,
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
});
|
};
|
||||||
|
|
||||||
|
// As it happens, and what the mesh already held when this module asked what it missed.
|
||||||
|
await on("mesh-build-machine.built", placeTheBuild);
|
||||||
|
await on("mesh-controller.built-before", placeTheBuild);
|
||||||
|
|
||||||
// **And ask for what was built before this catalogue existed** (novox/hq 04-ISSUES/050).
|
// **And ask for what was built before this catalogue existed** (novox/hq 04-ISSUES/050).
|
||||||
//
|
//
|
||||||
|
|||||||
@@ -29,13 +29,16 @@
|
|||||||
"broker": "/var/lib/mesh/mesh-catalog/broker"
|
"broker": "/var/lib/mesh/mesh-catalog/broker"
|
||||||
},
|
},
|
||||||
"consumes": [
|
"consumes": [
|
||||||
"mesh-build-machine.built"
|
"mesh-build-machine.built",
|
||||||
|
"mesh-controller.built-before"
|
||||||
],
|
],
|
||||||
"emits": [
|
"emits": [
|
||||||
"registered",
|
"registered",
|
||||||
"upgraded",
|
"upgraded",
|
||||||
"rebuild-needed"
|
"rebuild-needed",
|
||||||
|
"catching-up"
|
||||||
],
|
],
|
||||||
|
"prepares": true,
|
||||||
"resources": [
|
"resources": [
|
||||||
{
|
{
|
||||||
"id": "mesh-state",
|
"id": "mesh-state",
|
||||||
|
|||||||
@@ -0,0 +1,17 @@
|
|||||||
|
// The catalogue's state, brought to the shape this version needs (novox/hq ADR 0135).
|
||||||
|
//
|
||||||
|
// **The mesh runs this before the version that needs it, and does not start that version if it
|
||||||
|
// fails** — and the refusal reaches this module and nothing else on the machine
|
||||||
|
// (novox/hq ADR 0136). That is the whole difference from where this used to happen: at start, inside
|
||||||
|
// the runtime, a schema that could not be brought up was a crash loop, the graph kept a gap, and
|
||||||
|
// nothing anywhere said so.
|
||||||
|
//
|
||||||
|
// Nothing here connects to the broker. Preparation runs before the version that would use it, so
|
||||||
|
// there is nothing yet to talk to; the runtime's `prepare` mode imports this and awaits it, and this
|
||||||
|
// process exiting non-zero is how the host knows not to start the runtime.
|
||||||
|
import { Graph } from "../store.js";
|
||||||
|
|
||||||
|
const graph = Graph.fromEnv();
|
||||||
|
await graph.migrate();
|
||||||
|
console.log("[mesh-catalog] the module graph's schema is what this version needs");
|
||||||
|
await graph.close();
|
||||||
@@ -12,6 +12,7 @@
|
|||||||
"pg.d.ts",
|
"pg.d.ts",
|
||||||
"store.ts",
|
"store.ts",
|
||||||
"index.ts",
|
"index.ts",
|
||||||
"tools/index.ts"
|
"tools/index.ts",
|
||||||
|
"prepare/index.ts"
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -14,11 +14,11 @@
|
|||||||
"route": {
|
"route": {
|
||||||
"api": {
|
"api": {
|
||||||
"label": "files-api",
|
"label": "files-api",
|
||||||
"port": 9000
|
"endpoint": "s3"
|
||||||
},
|
},
|
||||||
"console": {
|
"console": {
|
||||||
"label": "files",
|
"label": "files",
|
||||||
"port": 9001
|
"endpoint": "console"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
@@ -31,12 +31,14 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "s3",
|
||||||
"port": 9000,
|
"port": 9000,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "the S3 endpoint"
|
"why": "the S3 endpoint"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "console",
|
||||||
"port": 9001,
|
"port": 9001,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -20,6 +20,7 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "database",
|
||||||
"port": 27017,
|
"port": 27017,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -34,12 +34,14 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "mqtt",
|
||||||
"port": 1883,
|
"port": 1883,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "modules on any machine that were granted a topic namespace"
|
"why": "modules on any machine that were granted a topic namespace"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "mqtt-websockets",
|
||||||
"port": 8081,
|
"port": 8081,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -20,6 +20,7 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "database",
|
||||||
"port": 4848,
|
"port": 4848,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -14,7 +14,7 @@
|
|||||||
},
|
},
|
||||||
"route": {
|
"route": {
|
||||||
"label": "n8n",
|
"label": "n8n",
|
||||||
"port": 5682
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
@@ -29,6 +29,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 5682,
|
"port": 5682,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -21,6 +21,7 @@
|
|||||||
"consumes": [],
|
"consumes": [],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "bus",
|
||||||
"port": 4222,
|
"port": 4222,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -13,7 +13,7 @@
|
|||||||
},
|
},
|
||||||
"route": {
|
"route": {
|
||||||
"label": "drive",
|
"label": "drive",
|
||||||
"port": 80
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
@@ -38,6 +38,7 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 80,
|
"port": 80,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -12,6 +12,7 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 1880,
|
"port": 1880,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
@@ -81,7 +82,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "nodered",
|
"label": "nodered",
|
||||||
"port": 1880
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
|
|||||||
@@ -10,7 +10,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "@",
|
"label": "@",
|
||||||
"port": 4000
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
@@ -18,6 +18,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 4000,
|
"port": 4000,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -15,6 +15,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 6789,
|
"port": 6789,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
@@ -80,7 +81,7 @@
|
|||||||
],
|
],
|
||||||
"env": {
|
"env": {
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||||
"MESH_NZBGET_URL": "http://127.0.0.1:6789",
|
"MESH_NZBGET_URL": "http://127.0.0.1:${port:6789}",
|
||||||
"MESH_NZBGET_PASSWORD_FILE": "/run/secrets/password",
|
"MESH_NZBGET_PASSWORD_FILE": "/run/secrets/password",
|
||||||
"MESH_NZBGET_CONFIG_FILE": "/run/config/config.json",
|
"MESH_NZBGET_CONFIG_FILE": "/run/config/config.json",
|
||||||
"MESH_NZBGET_CONFIG_DIR": "/var/lib/nzbget/config"
|
"MESH_NZBGET_CONFIG_DIR": "/var/lib/nzbget/config"
|
||||||
|
|||||||
@@ -12,6 +12,7 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "api",
|
||||||
"port": 11434,
|
"port": 11434,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "machine",
|
"from": "machine",
|
||||||
|
|||||||
@@ -13,7 +13,7 @@ ARG RUNTIME_BASE
|
|||||||
FROM ${BUILD_BASE} AS build
|
FROM ${BUILD_BASE} AS build
|
||||||
WORKDIR /app/modules/ombi
|
WORKDIR /app/modules/ombi
|
||||||
COPY . .
|
COPY . .
|
||||||
RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts \
|
RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts servarr/settings.ts plex/settings.ts connections/index.ts \
|
||||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
||||||
|
|
||||||
FROM ${RUNTIME_BASE}
|
FROM ${RUNTIME_BASE}
|
||||||
@@ -22,3 +22,6 @@ COPY --from=build /app/modules/ombi/dist /app/modules/ombi/dist
|
|||||||
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
|
||||||
# the convention novox/hq issues 060/061 settled.
|
# the convention novox/hq issues 060/061 settled.
|
||||||
ENV MESH_TOOL_MODULES=/app/modules/ombi/dist/index.js,/app/modules/ombi/dist/tools/index.js
|
ENV MESH_TOOL_MODULES=/app/modules/ombi/dist/index.js,/app/modules/ombi/dist/tools/index.js
|
||||||
|
# NOT dist/connections/index.js: that is a step the host runs to completion, named by the `connections`
|
||||||
|
# container's args as `mesh-tools run …` (novox/hq ADR 0052). Listed here it would run inside the
|
||||||
|
# serving sidecar too, and exit it.
|
||||||
|
|||||||
@@ -0,0 +1,66 @@
|
|||||||
|
// ombi's connections step — run once by the host after ombi's server starts, and run again whenever
|
||||||
|
// a binding or pair credential it reads changes (the container's `restart-on`, novox/hq ADR 0099).
|
||||||
|
// It brings ombi's connections to Sonarr, Radarr, Lidarr (servarr/settings.ts) and Plex
|
||||||
|
// (plex/settings.ts) in line with what the mesh bound.
|
||||||
|
//
|
||||||
|
// **A step, not a loop**, for the reason route-adapter gives: everything it does is a function of
|
||||||
|
// files the mesh writes, and the host already knows when they change. It connects to no broker.
|
||||||
|
//
|
||||||
|
// Exits non-zero when any app could not be put right — a refused credential, an unreachable app, an
|
||||||
|
// ombi that cannot reach it — so the node reports the step failed and the host runs it again on the
|
||||||
|
// next apply. It is declared last in the manifest, so its failing gates nothing else of ombi's
|
||||||
|
// (novox/hq ADR 0136). One app failing does not stop the others being put right.
|
||||||
|
//
|
||||||
|
// Reads, per provision, `<dir>/<provision>.json` (the binding) and `<dir>/<provision>.secret` (the
|
||||||
|
// pair credential), where <dir> is MESH_CONNECTIONS_DIR. Never prints a key or a token.
|
||||||
|
|
||||||
|
import { join } from "node:path";
|
||||||
|
|
||||||
|
import { PLEX_PROVISION, reconcilePlex } from "../plex/settings.js";
|
||||||
|
import { APPS, ombiReady, readBinding, readIfThere, reconcileApp, type Http, type Outcome } from "../servarr/settings.js";
|
||||||
|
|
||||||
|
const dir = process.env.MESH_CONNECTIONS_DIR ?? "/run/connections";
|
||||||
|
const url = process.env.MESH_OMBI_URL ?? "http://127.0.0.1:3579";
|
||||||
|
const apiKey = (await readIfThere(process.env.MESH_OMBI_API_KEY_FILE))?.trim() ?? process.env.MESH_OMBI_API_KEY ?? "";
|
||||||
|
const waitSeconds = Number(process.env.MESH_OMBI_WAIT_SECONDS ?? "180");
|
||||||
|
|
||||||
|
// Every call bounded: an entry ombi keeps may name a host that no longer answers, and a step that
|
||||||
|
// hangs on it holds the apply.
|
||||||
|
const http: Http = { fetch: (u, init) => fetch(u, { ...init, signal: AbortSignal.timeout(20_000) }) };
|
||||||
|
|
||||||
|
if (!apiKey) {
|
||||||
|
console.error("[ombi-connections] no ombi API key — ombi's own `api-key` secret has not been accepted");
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
const ombi = { url, apiKey };
|
||||||
|
|
||||||
|
if (!(await ombiReady(http, ombi, waitSeconds * 1000))) {
|
||||||
|
console.error(`[ombi-connections] ombi did not answer at ${url} within ${waitSeconds}s`);
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
|
||||||
|
const inputs = async (provision: string) =>
|
||||||
|
[await readBinding(join(dir, `${provision}.json`)), await readIfThere(join(dir, `${provision}.secret`))] as const;
|
||||||
|
|
||||||
|
const outcomes: Outcome[] = [];
|
||||||
|
for (const spec of APPS) {
|
||||||
|
outcomes.push(await reconcileApp(http, ombi, spec, ...(await inputs(spec.provision))));
|
||||||
|
}
|
||||||
|
outcomes.push(await reconcilePlex(http, ombi, ...(await inputs(PLEX_PROVISION))));
|
||||||
|
|
||||||
|
let failed = 0;
|
||||||
|
for (const outcome of outcomes) {
|
||||||
|
switch (outcome.result) {
|
||||||
|
case "unchanged":
|
||||||
|
console.log(`[ombi-connections] ${outcome.app}: already as the mesh says; connection tested`);
|
||||||
|
break;
|
||||||
|
case "written":
|
||||||
|
console.log(`[ombi-connections] ${outcome.app}: wrote ${outcome.fields.join(", ")}; connection tested`);
|
||||||
|
break;
|
||||||
|
case "refused":
|
||||||
|
failed++;
|
||||||
|
console.error(`[ombi-connections] ${outcome.app}: ${outcome.problem}`);
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
process.exitCode = failed > 0 ? 1 : 0;
|
||||||
+67
-11
@@ -14,6 +14,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 3579,
|
"port": 3579,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
@@ -27,10 +28,15 @@
|
|||||||
"path": "/var/lib/mesh/ombi",
|
"path": "/var/lib/mesh/ombi",
|
||||||
"mode": "0700"
|
"mode": "0700"
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
"id": "state",
|
||||||
|
"type": "directory",
|
||||||
|
"mode": "0700",
|
||||||
|
"place": "."
|
||||||
|
},
|
||||||
{
|
{
|
||||||
"id": "config",
|
"id": "config",
|
||||||
"type": "directory",
|
"type": "directory",
|
||||||
"path": "/services/ombi/config",
|
|
||||||
"mode": "0700",
|
"mode": "0700",
|
||||||
"owner": "1000:1000"
|
"owner": "1000:1000"
|
||||||
},
|
},
|
||||||
@@ -38,7 +44,7 @@
|
|||||||
"id": "server",
|
"id": "server",
|
||||||
"type": "container",
|
"type": "container",
|
||||||
"name": "ombi",
|
"name": "ombi",
|
||||||
"image": "lscr.io/linuxserver/ombi@sha256:a6f76ac521ba01eee2e9f0c23a3fed22e56630d97a04d5eeaeaa36c1e681640d",
|
"image": "lscr.io/linuxserver/ombi@sha256:22d6ebadbaaa728571353e74dc2173719e0fb02d4eaec551a7e9d2ee99ef68ac",
|
||||||
"env": {
|
"env": {
|
||||||
"PUID": "1000",
|
"PUID": "1000",
|
||||||
"PGID": "1000",
|
"PGID": "1000",
|
||||||
@@ -48,7 +54,7 @@
|
|||||||
"3579"
|
"3579"
|
||||||
],
|
],
|
||||||
"volumes": [
|
"volumes": [
|
||||||
"/services/ombi/config:/config"
|
"${dir:config}:/config"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
@@ -67,33 +73,83 @@
|
|||||||
"volumes": [
|
"volumes": [
|
||||||
"/var/lib/mesh/ombi/broker:/run/secrets/broker:ro",
|
"/var/lib/mesh/ombi/broker:/run/secrets/broker:ro",
|
||||||
"/var/lib/mesh/ombi/api-key:/run/secrets/api-key:ro",
|
"/var/lib/mesh/ombi/api-key:/run/secrets/api-key:ro",
|
||||||
"/var/lib/mesh/ombi/config.json:/run/config/config.json:ro",
|
"/var/lib/mesh/ombi/config.json:/run/config/config.json:ro"
|
||||||
"/services/ombi/config:/var/lib/ombi/config:ro"
|
|
||||||
],
|
],
|
||||||
"env": {
|
"env": {
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||||
"MESH_OMBI_URL": "http://127.0.0.1:3579",
|
"MESH_OMBI_URL": "http://127.0.0.1:${port:3579}",
|
||||||
"MESH_OMBI_API_KEY_FILE": "/run/secrets/api-key",
|
"MESH_OMBI_API_KEY_FILE": "/run/secrets/api-key",
|
||||||
"MESH_OMBI_CONFIG_FILE": "/run/config/config.json",
|
"MESH_OMBI_CONFIG_FILE": "/run/config/config.json"
|
||||||
"MESH_OMBI_CONFIG_DIR": "/var/lib/ombi/config"
|
|
||||||
},
|
},
|
||||||
"restart-on": [
|
"restart-on": [
|
||||||
"runtime-config"
|
"runtime-config"
|
||||||
],
|
],
|
||||||
"artifact": "runtime"
|
"artifact": "runtime"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "connections",
|
||||||
|
"type": "container",
|
||||||
|
"name": "mesh-ombi-connections",
|
||||||
|
"network": "host",
|
||||||
|
"run-once": true,
|
||||||
|
"volumes": [
|
||||||
|
"/var/lib/mesh/ombi/api-key:/run/secrets/api-key:ro",
|
||||||
|
"${dir:state}/sonarr-api.json:/run/connections/sonarr-api.json:ro",
|
||||||
|
"${dir:state}/sonarr-api.secret:/run/connections/sonarr-api.secret:ro",
|
||||||
|
"${dir:state}/radarr-api.json:/run/connections/radarr-api.json:ro",
|
||||||
|
"${dir:state}/radarr-api.secret:/run/connections/radarr-api.secret:ro",
|
||||||
|
"${dir:state}/lidarr-api.json:/run/connections/lidarr-api.json:ro",
|
||||||
|
"${dir:state}/lidarr-api.secret:/run/connections/lidarr-api.secret:ro",
|
||||||
|
"${dir:state}/plex-api.json:/run/connections/plex-api.json:ro",
|
||||||
|
"${dir:state}/plex-api.secret:/run/connections/plex-api.secret:ro"
|
||||||
|
],
|
||||||
|
"env": {
|
||||||
|
"MESH_OMBI_URL": "http://127.0.0.1:${port:3579}",
|
||||||
|
"MESH_OMBI_API_KEY_FILE": "/run/secrets/api-key",
|
||||||
|
"MESH_CONNECTIONS_DIR": "/run/connections"
|
||||||
|
},
|
||||||
|
"args": [
|
||||||
|
"run",
|
||||||
|
"/app/modules/ombi/dist/connections/index.js"
|
||||||
|
],
|
||||||
|
"restart-on": [
|
||||||
|
"bound-sonarr-api",
|
||||||
|
"secret-sonarr-api",
|
||||||
|
"bound-radarr-api",
|
||||||
|
"secret-radarr-api",
|
||||||
|
"bound-lidarr-api",
|
||||||
|
"secret-lidarr-api",
|
||||||
|
"bound-plex-api",
|
||||||
|
"secret-plex-api"
|
||||||
|
],
|
||||||
|
"artifact": "runtime"
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"requires": [
|
"requires": [
|
||||||
"route"
|
"lidarr-api",
|
||||||
|
"plex-api",
|
||||||
|
"radarr-api",
|
||||||
|
"route",
|
||||||
|
"sonarr-api"
|
||||||
],
|
],
|
||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "ombi",
|
"label": "ombi",
|
||||||
"port": 3579
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
"route": "/var/lib/mesh/ombi/route.json"
|
"route": "${dir:state}/route.json",
|
||||||
|
"sonarr-api": "${dir:state}/sonarr-api.json",
|
||||||
|
"radarr-api": "${dir:state}/radarr-api.json",
|
||||||
|
"lidarr-api": "${dir:state}/lidarr-api.json",
|
||||||
|
"plex-api": "${dir:state}/plex-api.json"
|
||||||
|
},
|
||||||
|
"secrets": {
|
||||||
|
"sonarr-api": "${dir:state}/sonarr-api.secret",
|
||||||
|
"radarr-api": "${dir:state}/radarr-api.secret",
|
||||||
|
"lidarr-api": "${dir:state}/lidarr-api.secret",
|
||||||
|
"plex-api": "${dir:state}/plex-api.secret"
|
||||||
},
|
},
|
||||||
"build": {
|
"build": {
|
||||||
"on": [
|
"on": [
|
||||||
|
|||||||
@@ -4,6 +4,11 @@
|
|||||||
"description": "ombi — media requests. Its API client, tools and events live here (novox/hq ADR 0039).",
|
"description": "ombi — media requests. Its API client, tools and events live here (novox/hq ADR 0039).",
|
||||||
"type": "module",
|
"type": "module",
|
||||||
"private": true,
|
"private": true,
|
||||||
|
"scripts": {
|
||||||
|
"build": "tsc client.ts index.ts tools/index.ts servarr/settings.ts plex/settings.ts connections/index.ts --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist",
|
||||||
|
"typecheck": "tsc -p tsconfig.json",
|
||||||
|
"test": "npm run build && node --test --experimental-strip-types 'test/*.test.ts'"
|
||||||
|
},
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@novox/mesh-sdk": "^0.1.0"
|
"@novox/mesh-sdk": "^0.1.0"
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -0,0 +1,271 @@
|
|||||||
|
// Where ombi reaches Plex — decided by the mesh, written into ombi by ombi's own API.
|
||||||
|
//
|
||||||
|
// **Why this exists.** ombi keeps its Plex servers in its own database (OmbiSettings.db), so the
|
||||||
|
// mesh has no file to write `${bound:plex-api:at}` into. ombi requires `plex-api`; the mesh delivers
|
||||||
|
// a binding (where plex is: `at`, and what it serves: `port`, `scheme`) and a pair credential (the
|
||||||
|
// server owner's X-Plex-Token, accepted by the operator — plex.tv issues it and the mesh cannot
|
||||||
|
// mint it). This step makes ombi's Plex settings say the same thing, beside its Servarr ones.
|
||||||
|
//
|
||||||
|
// **Which entry is plex's.** ombi may list several Plex servers. The one this provision names is
|
||||||
|
// found by the server's own machineIdentifier, which plex answers at /identity — the same value
|
||||||
|
// ombi stored when an operator loaded the server in its settings screen. That entry's connection is
|
||||||
|
// brought in line; an entry for any other server is never touched.
|
||||||
|
//
|
||||||
|
// When no entry carries that identifier, an entry may still be this server reached another way:
|
||||||
|
// ace's ombi holds one loaded from an older server and later retyped to plex's public name, so its
|
||||||
|
// stored identifier is stale while its address answers as this plex. Each entry's OWN address is
|
||||||
|
// asked for /identity, and an entry plex itself answers for is this server's — adopted: its
|
||||||
|
// connection laid over and its identifier corrected (ombi builds its "view in Plex" links from it).
|
||||||
|
// Nothing is guessed: an entry whose address is unreachable, or answers as another server, is left
|
||||||
|
// as it was. Only when no entry is this server's either way is one added, named as plex names
|
||||||
|
// itself — it is the mesh's, so later runs keep it true.
|
||||||
|
//
|
||||||
|
// **Only the connection, and only when it differs.** Host, port, TLS, base path and token — and the
|
||||||
|
// identifier of an adopted entry. Whether Plex is enabled in ombi, watchlist import, the selected
|
||||||
|
// libraries, the batch size and everything else an operator chose are left exactly as they are.
|
||||||
|
//
|
||||||
|
// **A token plex refuses is never written.** Until the operator accepts the server's token for this
|
||||||
|
// pair, the mesh delivers a value it minted itself, which plex answers with 401 (or 400 on its own
|
||||||
|
// network). Writing it would replace a working token in ombi with a dead one, so the token is tried
|
||||||
|
// against plex first; refused, nothing is written and the step fails naming the `secret accept`.
|
||||||
|
|
||||||
|
import { isLoopback, ombiCall, type Binding, type Http, type Ombi, type Outcome } from "../servarr/settings.js";
|
||||||
|
|
||||||
|
/** The provision ombi requires for Plex — the manifest's `requires`, `binds` and `secrets` key. */
|
||||||
|
export const PLEX_PROVISION = "plex-api";
|
||||||
|
|
||||||
|
/** The connection fields ombi keeps for a Plex server — the only ones this step ever writes. */
|
||||||
|
export interface PlexConnection {
|
||||||
|
ip: string;
|
||||||
|
port: number;
|
||||||
|
ssl: boolean;
|
||||||
|
subDir: string | null;
|
||||||
|
plexAuthToken: string;
|
||||||
|
}
|
||||||
|
|
||||||
|
export type PlexWanted = { ok: true; connection: PlexConnection; from: string } | { ok: false; problem: string };
|
||||||
|
|
||||||
|
/** The connection the mesh says ombi should use, from the binding and the pair credential. */
|
||||||
|
export function wantedPlex(binding: Binding | undefined, credential: string | undefined): PlexWanted {
|
||||||
|
if (!binding) {
|
||||||
|
return { ok: false, problem: `no binding for ${PLEX_PROVISION} was delivered — the mesh writes it before this step runs` };
|
||||||
|
}
|
||||||
|
const at = typeof binding.at === "string" ? binding.at.trim() : "";
|
||||||
|
const serves = binding.serves ?? {};
|
||||||
|
const port = Number(serves.port);
|
||||||
|
if (!at) return { ok: false, problem: `the ${PLEX_PROVISION} binding names no host (at)` };
|
||||||
|
if (isLoopback(at)) {
|
||||||
|
return {
|
||||||
|
ok: false,
|
||||||
|
problem:
|
||||||
|
`the ${PLEX_PROVISION} binding says plex is at ${at}, which from ombi's own container is ombi itself. ` +
|
||||||
|
`The mesh hands loopback to a machine that is not on the private network; put it on the private ` +
|
||||||
|
`network so plex has an address ombi can dial`,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
if (!Number.isInteger(port) || port <= 0 || port > 65535) {
|
||||||
|
return { ok: false, problem: `the ${PLEX_PROVISION} binding serves no usable port (${String(serves.port)})` };
|
||||||
|
}
|
||||||
|
const scheme = typeof serves.scheme === "string" && serves.scheme ? serves.scheme : "http";
|
||||||
|
if (scheme !== "http" && scheme !== "https") {
|
||||||
|
return { ok: false, problem: `the ${PLEX_PROVISION} binding serves scheme ${scheme}, which ombi cannot dial` };
|
||||||
|
}
|
||||||
|
const token = (credential ?? "").trim();
|
||||||
|
if (!token) return { ok: false, problem: `the ${PLEX_PROVISION} credential is empty or was not delivered` };
|
||||||
|
return {
|
||||||
|
ok: true,
|
||||||
|
from: typeof binding.from === "string" ? binding.from : "",
|
||||||
|
connection: { ip: at, port, ssl: scheme === "https", subDir: null, plexAuthToken: token },
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
/** plex's base URL as the step dials it — the same host and port ombi will be given. */
|
||||||
|
export function plexUrl(want: PlexConnection): string {
|
||||||
|
const host = want.ip.includes(":") && !want.ip.startsWith("[") ? `[${want.ip}]` : want.ip;
|
||||||
|
return `${want.ssl ? "https" : "http"}://${host}:${want.port}`;
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Which connection fields differ between an entry ombi holds and what the mesh says. Names only. */
|
||||||
|
export function differingPlex(current: Record<string, unknown> | undefined, want: PlexConnection): (keyof PlexConnection)[] {
|
||||||
|
const now = current ?? {};
|
||||||
|
const out: (keyof PlexConnection)[] = [];
|
||||||
|
if (String(now.ip ?? "") !== want.ip) out.push("ip");
|
||||||
|
if (Number(now.port ?? 0) !== want.port) out.push("port");
|
||||||
|
if (Boolean(now.ssl) !== want.ssl) out.push("ssl");
|
||||||
|
const sub = typeof now.subDir === "string" && now.subDir.trim() !== "" ? now.subDir : null;
|
||||||
|
if (sub !== want.subDir) out.push("subDir");
|
||||||
|
if (String(now.plexAuthToken ?? "") !== want.plexAuthToken) out.push("plexAuthToken");
|
||||||
|
return out;
|
||||||
|
}
|
||||||
|
|
||||||
|
async function plexGet(http: Http, want: PlexConnection, path: string, withToken: boolean) {
|
||||||
|
const headers: Record<string, string> = { Accept: "application/json" };
|
||||||
|
if (withToken) headers["X-Plex-Token"] = want.plexAuthToken;
|
||||||
|
return http.fetch(`${plexUrl(want)}${path}`, { method: "GET", headers });
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Does plex take this token? `true` it does; `false` it refused it — 401 or 403, or 400, which is
|
||||||
|
* what plex answers a token it never issued on a network it trusts. A thrown error when plex could
|
||||||
|
* not be asked.
|
||||||
|
*/
|
||||||
|
export async function plexTakes(http: Http, want: PlexConnection): Promise<{ takes: boolean; friendlyName?: string }> {
|
||||||
|
const res = await plexGet(http, want, "/", true);
|
||||||
|
if (res.status === 400 || res.status === 401 || res.status === 403) return { takes: false };
|
||||||
|
if (res.status < 200 || res.status >= 300) throw new Error(`plex answered ${res.status} at /`);
|
||||||
|
let friendlyName: string | undefined;
|
||||||
|
try {
|
||||||
|
const body = JSON.parse(await res.text()) as { MediaContainer?: { friendlyName?: unknown } };
|
||||||
|
if (typeof body.MediaContainer?.friendlyName === "string") friendlyName = body.MediaContainer.friendlyName;
|
||||||
|
} catch {
|
||||||
|
// a name is a nicety for a new entry, not a condition
|
||||||
|
}
|
||||||
|
return { takes: true, friendlyName };
|
||||||
|
}
|
||||||
|
|
||||||
|
/** The server's own machineIdentifier, which plex answers without a token. */
|
||||||
|
export async function plexIdentity(http: Http, want: Pick<PlexConnection, "ip" | "port" | "ssl" | "subDir">): Promise<string> {
|
||||||
|
const host = want.ip.includes(":") && !want.ip.startsWith("[") ? `[${want.ip}]` : want.ip;
|
||||||
|
const base = `${want.ssl ? "https" : "http"}://${host}:${want.port}${want.subDir ? `/${want.subDir.replace(/^\/+|\/+$/g, "")}` : ""}`;
|
||||||
|
const res = await http.fetch(`${base}/identity`, { method: "GET", headers: { Accept: "application/json" } });
|
||||||
|
if (res.status !== 200) throw new Error(`plex answered ${res.status} at /identity`);
|
||||||
|
const body = JSON.parse(await res.text()) as { MediaContainer?: { machineIdentifier?: unknown } };
|
||||||
|
const id = body.MediaContainer?.machineIdentifier;
|
||||||
|
if (typeof id !== "string" || id === "") throw new Error("plex's /identity names no machineIdentifier");
|
||||||
|
return id;
|
||||||
|
}
|
||||||
|
|
||||||
|
/** The remedy for a refused token, in the controller's own words (ADR 0092). */
|
||||||
|
export function plexAcceptRemedy(from: string): string {
|
||||||
|
return (
|
||||||
|
`plex refuses the ${PLEX_PROVISION} credential the mesh delivered, so it was not written into ombi. ` +
|
||||||
|
`plex's token is issued by plex.tv and the mesh cannot make it: accept the server's own token for ` +
|
||||||
|
`this pair — \`secret accept <this node> ombi ${PLEX_PROVISION} --provider ${from || "<its node>"} ` +
|
||||||
|
`--from <file holding the server's X-Plex-Token>\``
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/** The batch size ombi's settings screen fills in for a server it adds ("150 by default"). */
|
||||||
|
const EPISODE_BATCH_SIZE = 150;
|
||||||
|
|
||||||
|
/** ombi's server entries, as its settings document holds them (null on a fresh ombi). */
|
||||||
|
export function serversOf(document: Record<string, unknown> | undefined): Record<string, unknown>[] {
|
||||||
|
const servers = document?.servers;
|
||||||
|
return Array.isArray(servers) ? (servers as Record<string, unknown>[]) : [];
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Which entries, holding another identifier, plex answers for at their own address — this server,
|
||||||
|
* reached another way. Asked only when no entry carries the identifier. An entry that cannot be
|
||||||
|
* asked is not this server's: nothing is guessed.
|
||||||
|
*/
|
||||||
|
export async function answeringAs(http: Http, servers: Record<string, unknown>[], machineIdentifier: string): Promise<Set<number>> {
|
||||||
|
const out = new Set<number>();
|
||||||
|
if (servers.some((s) => s?.machineIdentifier === machineIdentifier)) return out;
|
||||||
|
for (const [i, s] of servers.entries()) {
|
||||||
|
const ip = typeof s?.ip === "string" ? s.ip.trim() : "";
|
||||||
|
const port = Number(s?.port);
|
||||||
|
if (!ip || !Number.isInteger(port) || port <= 0 || port > 65535) continue;
|
||||||
|
const subDir = typeof s.subDir === "string" && s.subDir.trim() !== "" ? s.subDir : null;
|
||||||
|
try {
|
||||||
|
if ((await plexIdentity(http, { ip, port, ssl: Boolean(s.ssl), subDir })) === machineIdentifier) out.add(i);
|
||||||
|
} catch {
|
||||||
|
// unreachable, or not a plex: not this server's
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return out;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* ombi's Plex settings with this server's connection laid over them: every entry naming the
|
||||||
|
* server's machineIdentifier — or adopted, its address answering as this server — gets the
|
||||||
|
* connection (an adopted one also the identifier), every other entry is left as it was, and when
|
||||||
|
* none is this server's one is added. Returns the document to save and the fields that changed.
|
||||||
|
*/
|
||||||
|
export function withPlexServer(
|
||||||
|
document: Record<string, unknown> | undefined,
|
||||||
|
machineIdentifier: string,
|
||||||
|
want: PlexConnection,
|
||||||
|
name: string,
|
||||||
|
adopted: ReadonlySet<number> = new Set(),
|
||||||
|
): { next: Record<string, unknown>; fields: string[]; added: boolean; entry: Record<string, unknown> } {
|
||||||
|
const doc = document ?? {};
|
||||||
|
const servers = serversOf(doc);
|
||||||
|
const fields = new Set<string>();
|
||||||
|
let entry: Record<string, unknown> | undefined;
|
||||||
|
const next = servers.map((s, i) => {
|
||||||
|
const adopt = adopted.has(i) && s?.machineIdentifier !== machineIdentifier;
|
||||||
|
if (s?.machineIdentifier !== machineIdentifier && !adopt) return s;
|
||||||
|
for (const f of differingPlex(s, want)) fields.add(f);
|
||||||
|
if (adopt) fields.add("machineIdentifier");
|
||||||
|
const laid = { ...s, machineIdentifier, ip: want.ip, port: want.port, ssl: want.ssl, subDir: want.subDir, plexAuthToken: want.plexAuthToken };
|
||||||
|
entry ??= laid;
|
||||||
|
return laid;
|
||||||
|
});
|
||||||
|
if (entry) return { next: { ...doc, servers: next }, fields: [...fields], added: false, entry };
|
||||||
|
const added: Record<string, unknown> = {
|
||||||
|
name,
|
||||||
|
machineIdentifier,
|
||||||
|
ip: want.ip,
|
||||||
|
port: want.port,
|
||||||
|
ssl: want.ssl,
|
||||||
|
subDir: want.subDir,
|
||||||
|
plexAuthToken: want.plexAuthToken,
|
||||||
|
episodeBatchSize: EPISODE_BATCH_SIZE,
|
||||||
|
plexSelectedLibraries: [],
|
||||||
|
};
|
||||||
|
return { next: { ...doc, servers: [...next, added] }, fields: ["server"], added: true, entry: added };
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Bring ombi's connection to plex in line with the mesh: check the token against plex, find the
|
||||||
|
* server's entry by its machineIdentifier, write only the connection fields when they differ (or add
|
||||||
|
* the entry), then have ombi test the connection from its own container. Never throws.
|
||||||
|
*/
|
||||||
|
export async function reconcilePlex(http: Http, ombi: Ombi, binding: Binding | undefined, credential: string | undefined): Promise<Outcome> {
|
||||||
|
const app = "plex";
|
||||||
|
const w = wantedPlex(binding, credential);
|
||||||
|
// `in`, not `!w.ok`: the Dockerfile compiles without strict, where a boolean discriminant does not
|
||||||
|
// narrow.
|
||||||
|
if ("problem" in w) return { app, result: "refused", problem: w.problem };
|
||||||
|
const want = w.connection;
|
||||||
|
|
||||||
|
let name: string;
|
||||||
|
let machineIdentifier: string;
|
||||||
|
try {
|
||||||
|
const taken = await plexTakes(http, want);
|
||||||
|
if (!taken.takes) return { app, result: "refused", problem: plexAcceptRemedy(w.from) };
|
||||||
|
machineIdentifier = await plexIdentity(http, want);
|
||||||
|
name = taken.friendlyName || "Plex";
|
||||||
|
} catch (err) {
|
||||||
|
return { app, result: "refused", problem: `plex could not be asked whether it takes the token at ${want.ip}:${want.port}: ${message(err)}` };
|
||||||
|
}
|
||||||
|
|
||||||
|
try {
|
||||||
|
const document = (await ombiCall(http, ombi, "GET", "/Settings/Plex")) as Record<string, unknown> | undefined;
|
||||||
|
const adopted = await answeringAs(http, serversOf(document), machineIdentifier);
|
||||||
|
const laid = withPlexServer(document, machineIdentifier, want, name, adopted);
|
||||||
|
if (laid.fields.length > 0) {
|
||||||
|
const saved = await ombiCall(http, ombi, "POST", "/Settings/Plex", laid.next);
|
||||||
|
if (saved === false) return { app, result: "refused", problem: "ombi declined to save its Plex settings" };
|
||||||
|
}
|
||||||
|
// ombi's own test, from ombi's own container — the path the step's check above did not take.
|
||||||
|
const tested = await ombiCall(http, ombi, "POST", "/Tester/plex", laid.entry);
|
||||||
|
if (tested !== true) {
|
||||||
|
return {
|
||||||
|
app,
|
||||||
|
result: "refused",
|
||||||
|
problem:
|
||||||
|
`ombi cannot reach plex at ${want.ip}:${want.port} from its own container` +
|
||||||
|
(laid.fields.length > 0 ? `; its settings were written (${laid.fields.join(", ")})` : ""),
|
||||||
|
};
|
||||||
|
}
|
||||||
|
return laid.fields.length > 0 ? { app, result: "written", fields: laid.fields } : { app, result: "unchanged" };
|
||||||
|
} catch (err) {
|
||||||
|
return { app, result: "refused", problem: message(err) };
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
function message(err: unknown): string {
|
||||||
|
return err instanceof Error ? err.message : String(err);
|
||||||
|
}
|
||||||
@@ -0,0 +1,304 @@
|
|||||||
|
// Where ombi reaches Sonarr, Radarr and Lidarr — decided by the mesh, written into ombi by ombi's
|
||||||
|
// own API.
|
||||||
|
//
|
||||||
|
// **Why this exists.** ombi keeps its connection to each Servarr app in its own database
|
||||||
|
// (OmbiSettings.db), not in a file, so the mesh has nowhere to write `${bound:sonarr-api:at}` for it.
|
||||||
|
// ombi requires `sonarr-api`, `radarr-api` and `lidarr-api`; the mesh delivers, for each, a binding
|
||||||
|
// (where the app is: `at`, and what it serves: `port`, `scheme`, `url-base`) and a pair credential
|
||||||
|
// (the app's API key, accepted by the operator — a Servarr app has exactly one key and the mesh
|
||||||
|
// cannot mint it). This step reads those files and makes ombi's settings say the same thing.
|
||||||
|
//
|
||||||
|
// **Only the connection, and only when it differs.** Host, port, TLS, base path and API key. The
|
||||||
|
// quality profile, root folder, language profile, tags, "enabled" and every other choice an operator
|
||||||
|
// made in ombi's settings screen are left exactly as they are: the mesh knows where the app is, not
|
||||||
|
// what ombi should do with it. Radarr's 4K instance is a different Radarr and is not touched.
|
||||||
|
//
|
||||||
|
// **A credential the app refuses is never written.** Until the operator accepts the app's API key
|
||||||
|
// for this pair, the mesh delivers a value it minted itself, which no Servarr app will ever accept
|
||||||
|
// (novox/hq ADR 0092). Writing it would replace a working key in ombi with a dead one. So the key is
|
||||||
|
// tried against the app first; refused, nothing for that app is written and the step fails naming
|
||||||
|
// the `secret accept` that fixes it.
|
||||||
|
//
|
||||||
|
// Pure logic and a small HTTP seam, so it is tested against fake servers (test/servarr.test.ts).
|
||||||
|
|
||||||
|
import { readFile } from "node:fs/promises";
|
||||||
|
|
||||||
|
/** One Servarr app ombi connects to, and the shape of that connection in ombi's API. */
|
||||||
|
export interface ServarrApp {
|
||||||
|
/** The app, as ombi's API names it: /Settings/<app>, /Tester/<app>. */
|
||||||
|
app: "sonarr" | "radarr" | "lidarr";
|
||||||
|
/** The provision it is required as — the manifest's `requires`, `binds` and `secrets` key. */
|
||||||
|
provision: string;
|
||||||
|
/** The app's own status endpoint, which answers 401 to a wrong key. */
|
||||||
|
statusPath: string;
|
||||||
|
/**
|
||||||
|
* Where the one connection sits in ombi's settings document. Radarr's is `{radarr, radarr4K}`
|
||||||
|
* (two Radarr instances); only `radarr` is this provision's.
|
||||||
|
*/
|
||||||
|
within?: string;
|
||||||
|
}
|
||||||
|
|
||||||
|
export const APPS: readonly ServarrApp[] = [
|
||||||
|
{ app: "sonarr", provision: "sonarr-api", statusPath: "/api/v3/system/status" },
|
||||||
|
{ app: "radarr", provision: "radarr-api", statusPath: "/api/v3/system/status", within: "radarr" },
|
||||||
|
{ app: "lidarr", provision: "lidarr-api", statusPath: "/api/v1/system/status" },
|
||||||
|
];
|
||||||
|
|
||||||
|
/** The connection fields ombi keeps for an app — the only ones this step ever writes. */
|
||||||
|
export interface Connection {
|
||||||
|
ip: string;
|
||||||
|
port: number;
|
||||||
|
ssl: boolean;
|
||||||
|
/** ombi's name for the app's URL base; null when the app is served at the root. */
|
||||||
|
subDir: string | null;
|
||||||
|
apiKey: string;
|
||||||
|
}
|
||||||
|
|
||||||
|
/** What the mesh wrote at `binds.<provision>`: the binding document (controller's boundFile). */
|
||||||
|
export interface Binding {
|
||||||
|
provision?: string;
|
||||||
|
from?: string;
|
||||||
|
at?: string;
|
||||||
|
as?: string;
|
||||||
|
serves?: Record<string, unknown>;
|
||||||
|
}
|
||||||
|
|
||||||
|
export type Wanted = { ok: true; connection: Connection; from: string } | { ok: false; problem: string };
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The connection the mesh says ombi should use, from the binding and the pair credential.
|
||||||
|
*
|
||||||
|
* Refused rather than guessed when the binding cannot be dialled from ombi's own container: a
|
||||||
|
* loopback `at` — what the mesh hands a machine that is not on the private network — is ombi's
|
||||||
|
* container itself, not the app.
|
||||||
|
*/
|
||||||
|
export function wanted(spec: ServarrApp, binding: Binding | undefined, credential: string | undefined): Wanted {
|
||||||
|
if (!binding) {
|
||||||
|
return { ok: false, problem: `no binding for ${spec.provision} was delivered — the mesh writes it before this step runs` };
|
||||||
|
}
|
||||||
|
const at = typeof binding.at === "string" ? binding.at.trim() : "";
|
||||||
|
const serves = binding.serves ?? {};
|
||||||
|
const port = Number(serves.port);
|
||||||
|
if (!at) {
|
||||||
|
return { ok: false, problem: `the ${spec.provision} binding names no host (at)` };
|
||||||
|
}
|
||||||
|
if (isLoopback(at)) {
|
||||||
|
return {
|
||||||
|
ok: false,
|
||||||
|
problem:
|
||||||
|
`the ${spec.provision} binding says ${spec.app} is at ${at}, which from ombi's own container is ` +
|
||||||
|
`ombi itself. The mesh hands loopback to a machine that is not on the private network; put it ` +
|
||||||
|
`on the private network so ${spec.app} has an address ombi can dial`,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
if (!Number.isInteger(port) || port <= 0 || port > 65535) {
|
||||||
|
return { ok: false, problem: `the ${spec.provision} binding serves no usable port (${String(serves.port)})` };
|
||||||
|
}
|
||||||
|
const scheme = typeof serves.scheme === "string" && serves.scheme ? serves.scheme : "http";
|
||||||
|
if (scheme !== "http" && scheme !== "https") {
|
||||||
|
return { ok: false, problem: `the ${spec.provision} binding serves scheme ${scheme}, which ombi cannot dial` };
|
||||||
|
}
|
||||||
|
const key = (credential ?? "").trim();
|
||||||
|
if (!key) {
|
||||||
|
return { ok: false, problem: `the ${spec.provision} credential is empty or was not delivered` };
|
||||||
|
}
|
||||||
|
return {
|
||||||
|
ok: true,
|
||||||
|
from: typeof binding.from === "string" ? binding.from : "",
|
||||||
|
connection: { ip: at, port, ssl: scheme === "https", subDir: subDirOf(serves["url-base"]), apiKey: key },
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
/** ombi's `subDir`: the URL base with its slashes trimmed, null when there is none. */
|
||||||
|
export function subDirOf(urlBase: unknown): string | null {
|
||||||
|
const trimmed = typeof urlBase === "string" ? urlBase.trim().replace(/^\/+|\/+$/g, "") : "";
|
||||||
|
return trimmed === "" ? null : trimmed;
|
||||||
|
}
|
||||||
|
|
||||||
|
export function isLoopback(host: string): boolean {
|
||||||
|
const h = host.toLowerCase();
|
||||||
|
return h === "localhost" || h === "::1" || h === "[::1]" || /^127\./.test(h);
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Which connection fields differ between what ombi holds and what the mesh says. Names only. */
|
||||||
|
export function differing(current: Record<string, unknown> | undefined, want: Connection): (keyof Connection)[] {
|
||||||
|
const now = current ?? {};
|
||||||
|
const out: (keyof Connection)[] = [];
|
||||||
|
if (String(now.ip ?? "") !== want.ip) out.push("ip");
|
||||||
|
if (Number(now.port ?? 0) !== want.port) out.push("port");
|
||||||
|
if (Boolean(now.ssl) !== want.ssl) out.push("ssl");
|
||||||
|
if (subDirOf(now.subDir) !== want.subDir) out.push("subDir");
|
||||||
|
if (String(now.apiKey ?? "") !== want.apiKey) out.push("apiKey");
|
||||||
|
return out;
|
||||||
|
}
|
||||||
|
|
||||||
|
/** ombi's settings for the app with the connection laid over them and nothing else changed. */
|
||||||
|
export function withConnection(current: Record<string, unknown> | undefined, want: Connection): Record<string, unknown> {
|
||||||
|
return { ...(current ?? {}), ip: want.ip, port: want.port, ssl: want.ssl, subDir: want.subDir, apiKey: want.apiKey };
|
||||||
|
}
|
||||||
|
|
||||||
|
/** The app's base URL as the step dials it — the same host and port ombi will be given. */
|
||||||
|
export function appUrl(want: Connection): string {
|
||||||
|
const scheme = want.ssl ? "https" : "http";
|
||||||
|
const host = want.ip.includes(":") && !want.ip.startsWith("[") ? `[${want.ip}]` : want.ip;
|
||||||
|
return `${scheme}://${host}:${want.port}${want.subDir ? `/${want.subDir}` : ""}`;
|
||||||
|
}
|
||||||
|
|
||||||
|
/** How one app came out. */
|
||||||
|
export type Outcome =
|
||||||
|
| { app: string; result: "unchanged" }
|
||||||
|
| { app: string; result: "written"; fields: string[] }
|
||||||
|
| { app: string; result: "refused"; problem: string };
|
||||||
|
|
||||||
|
/** The HTTP the step needs, so a test can stand fakes in for ombi and the apps. */
|
||||||
|
export interface Http {
|
||||||
|
fetch(url: string, init?: { method?: string; headers?: Record<string, string>; body?: string }): Promise<{
|
||||||
|
status: number;
|
||||||
|
text(): Promise<string>;
|
||||||
|
}>;
|
||||||
|
}
|
||||||
|
|
||||||
|
export interface Ombi {
|
||||||
|
url: string;
|
||||||
|
apiKey: string;
|
||||||
|
}
|
||||||
|
|
||||||
|
export async function ombiCall(http: Http, ombi: Ombi, method: string, path: string, body?: unknown): Promise<unknown> {
|
||||||
|
const res = await http.fetch(`${ombi.url.replace(/\/$/, "")}/api/v1${path}`, {
|
||||||
|
method,
|
||||||
|
headers: {
|
||||||
|
ApiKey: ombi.apiKey,
|
||||||
|
Accept: "application/json",
|
||||||
|
...(body !== undefined ? { "Content-Type": "application/json" } : {}),
|
||||||
|
},
|
||||||
|
body: body !== undefined ? JSON.stringify(body) : undefined,
|
||||||
|
});
|
||||||
|
const text = await res.text();
|
||||||
|
if (res.status < 200 || res.status >= 300) {
|
||||||
|
// The body is ombi's error, never a request echo, so it carries no key.
|
||||||
|
throw new Error(`ombi ${method} ${path} answered ${res.status}${text ? `: ${text.slice(0, 200)}` : ""}`);
|
||||||
|
}
|
||||||
|
return text ? (JSON.parse(text) as unknown) : undefined;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Does the app take this key? `true` it does, `false` it refused it (401/403), and a thrown error
|
||||||
|
* when it could not be asked — unreachable, or answering something that is neither.
|
||||||
|
*/
|
||||||
|
export async function appTakes(http: Http, spec: ServarrApp, want: Connection): Promise<boolean> {
|
||||||
|
const res = await http.fetch(`${appUrl(want)}${spec.statusPath}`, {
|
||||||
|
method: "GET",
|
||||||
|
headers: { "X-Api-Key": want.apiKey, Accept: "application/json" },
|
||||||
|
});
|
||||||
|
if (res.status === 401 || res.status === 403) return false;
|
||||||
|
if (res.status >= 200 && res.status < 300) return true;
|
||||||
|
throw new Error(`${spec.app} answered ${res.status} at ${spec.statusPath}`);
|
||||||
|
}
|
||||||
|
|
||||||
|
/** The remedy for a refused key, in the controller's own words (ADR 0092). */
|
||||||
|
export function acceptRemedy(spec: ServarrApp, from: string): string {
|
||||||
|
return (
|
||||||
|
`${spec.app} refuses the ${spec.provision} credential the mesh delivered, so it was not written ` +
|
||||||
|
`into ombi. A Servarr app has one API key and the mesh cannot make it: accept ${spec.app}'s own ` +
|
||||||
|
`key for this pair — \`secret accept <this node> ombi ${spec.provision} --provider ${from || "<its node>"} ` +
|
||||||
|
`--from <file holding ${spec.app}'s ApiKey>\``
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Bring ombi's connection to one app in line with the mesh: check the key against the app, compare,
|
||||||
|
* write only the connection fields when they differ, then have ombi test the connection from its own
|
||||||
|
* container. Never throws: every failure is an outcome with a reason.
|
||||||
|
*/
|
||||||
|
export async function reconcileApp(
|
||||||
|
http: Http,
|
||||||
|
ombi: Ombi,
|
||||||
|
spec: ServarrApp,
|
||||||
|
binding: Binding | undefined,
|
||||||
|
credential: string | undefined,
|
||||||
|
): Promise<Outcome> {
|
||||||
|
const w = wanted(spec, binding, credential);
|
||||||
|
// `in`, not `!w.ok`: the Dockerfile compiles without strict, where a boolean discriminant does not
|
||||||
|
// narrow.
|
||||||
|
if ("problem" in w) return { app: spec.app, result: "refused", problem: w.problem };
|
||||||
|
const want = w.connection;
|
||||||
|
|
||||||
|
try {
|
||||||
|
if (!(await appTakes(http, spec, want))) {
|
||||||
|
return { app: spec.app, result: "refused", problem: acceptRemedy(spec, w.from) };
|
||||||
|
}
|
||||||
|
} catch (err) {
|
||||||
|
return {
|
||||||
|
app: spec.app,
|
||||||
|
result: "refused",
|
||||||
|
problem: `${spec.app} could not be asked whether it takes the key at ${want.ip}:${want.port}: ${message(err)}`,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
try {
|
||||||
|
const document = (await ombiCall(http, ombi, "GET", `/Settings/${spec.app}`)) as Record<string, unknown> | undefined;
|
||||||
|
const current = spec.within ? (document?.[spec.within] as Record<string, unknown> | undefined) : document;
|
||||||
|
const fields = differing(current, want);
|
||||||
|
if (fields.length > 0) {
|
||||||
|
const next = withConnection(current, want);
|
||||||
|
const body = spec.within ? { ...(document ?? {}), [spec.within]: next } : next;
|
||||||
|
const saved = await ombiCall(http, ombi, "POST", `/Settings/${spec.app}`, body);
|
||||||
|
if (saved === false) {
|
||||||
|
return { app: spec.app, result: "refused", problem: `ombi declined to save its ${spec.app} settings` };
|
||||||
|
}
|
||||||
|
}
|
||||||
|
// ombi's own test, from ombi's own container — the path the step's check above did not take.
|
||||||
|
const tested = (await ombiCall(http, ombi, "POST", `/Tester/${spec.app}`, withConnection(current, want))) as
|
||||||
|
| { isValid?: boolean; expectedSubDir?: string | null }
|
||||||
|
| undefined;
|
||||||
|
if (!tested?.isValid) {
|
||||||
|
const hint = tested?.expectedSubDir ? ` (ombi expected the base path ${tested.expectedSubDir})` : "";
|
||||||
|
return {
|
||||||
|
app: spec.app,
|
||||||
|
result: "refused",
|
||||||
|
problem:
|
||||||
|
`ombi cannot reach ${spec.app} at ${want.ip}:${want.port} from its own container${hint}` +
|
||||||
|
(fields.length > 0 ? `; its settings were written (${fields.join(", ")})` : ""),
|
||||||
|
};
|
||||||
|
}
|
||||||
|
return fields.length > 0 ? { app: spec.app, result: "written", fields } : { app: spec.app, result: "unchanged" };
|
||||||
|
} catch (err) {
|
||||||
|
return { app: spec.app, result: "refused", problem: message(err) };
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Wait for ombi to answer, because the step runs right after its container starts. */
|
||||||
|
export async function ombiReady(http: Http, ombi: Ombi, waitMs: number, pauseMs = 2000): Promise<boolean> {
|
||||||
|
const until = Date.now() + waitMs;
|
||||||
|
for (;;) {
|
||||||
|
try {
|
||||||
|
const res = await http.fetch(`${ombi.url.replace(/\/$/, "")}/api/v1/Status`, { method: "GET" });
|
||||||
|
if (res.status === 200) return true;
|
||||||
|
} catch {
|
||||||
|
// not listening yet
|
||||||
|
}
|
||||||
|
if (Date.now() >= until) return false;
|
||||||
|
await new Promise((r) => setTimeout(r, pauseMs));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/** A file the mesh wrote, or undefined when it is not there. */
|
||||||
|
export async function readIfThere(path: string | undefined): Promise<string | undefined> {
|
||||||
|
if (!path) return undefined;
|
||||||
|
return readFile(path, "utf8").catch(() => undefined);
|
||||||
|
}
|
||||||
|
|
||||||
|
/** A binding file parsed, or undefined when absent or not JSON. */
|
||||||
|
export async function readBinding(path: string | undefined): Promise<Binding | undefined> {
|
||||||
|
const raw = await readIfThere(path);
|
||||||
|
if (raw === undefined) return undefined;
|
||||||
|
try {
|
||||||
|
return JSON.parse(raw) as Binding;
|
||||||
|
} catch {
|
||||||
|
return undefined;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
function message(err: unknown): string {
|
||||||
|
return err instanceof Error ? err.message : String(err);
|
||||||
|
}
|
||||||
@@ -0,0 +1,223 @@
|
|||||||
|
// What holds ombi's Plex step (plex/settings.ts): the entry for the server plex says it is — found
|
||||||
|
// by machineIdentifier — is made to say what the mesh bound (host, port, TLS, token) and nothing
|
||||||
|
// else it keeps is touched; an entry for another server is left alone; an ombi with no entry for it
|
||||||
|
// gets one; nothing is written when nothing differs; and a token plex refuses (the mesh's own minted
|
||||||
|
// value, before the operator accepts the server's token) is never written, with the `secret accept`
|
||||||
|
// that fixes it named.
|
||||||
|
//
|
||||||
|
// ombi and plex are fakes answering the routes the step touches as the real ones do (checked against
|
||||||
|
// lscr.io/linuxserver/ombi 4.53.10 and plexinc/pms-docker 1.43.4: plex answers 401 to an unknown
|
||||||
|
// token from another network and 400 on one it trusts; ombi's /Tester/plex answers a bare boolean).
|
||||||
|
//
|
||||||
|
// Imports the compiled step, as keycloak's tests do: plex/settings.ts imports its sibling with the
|
||||||
|
// `.js` specifier the build needs, which Node's type stripping does not resolve to a `.ts` file.
|
||||||
|
|
||||||
|
import { test } from "node:test";
|
||||||
|
import assert from "node:assert/strict";
|
||||||
|
|
||||||
|
import { differingPlex, reconcilePlex, wantedPlex, withPlexServer } from "../dist/plex/settings.js";
|
||||||
|
import type { Binding, Http } from "../servarr/settings.ts";
|
||||||
|
|
||||||
|
const TOKEN = "the-servers-own-token";
|
||||||
|
const MACHINE = "5c47d9a165d10b622995d55b3ae1f168242f33bd";
|
||||||
|
const OMBI = { url: "http://127.0.0.1:3579", apiKey: "ombi-key" };
|
||||||
|
|
||||||
|
function binding(port = 32400, at = "ace.internal", scheme = "http"): Binding {
|
||||||
|
return { binding: 1, provision: "plex-api", from: "ace", at, as: "mesh_ace_ombi", serves: { scheme, port } } as Binding;
|
||||||
|
}
|
||||||
|
|
||||||
|
interface Call {
|
||||||
|
method: string;
|
||||||
|
url: string;
|
||||||
|
body?: unknown;
|
||||||
|
}
|
||||||
|
|
||||||
|
function fakes(plexSettings: Record<string, unknown>, opts: { reachable?: boolean; trusted?: boolean } = {}) {
|
||||||
|
const calls: Call[] = [];
|
||||||
|
const store = { plex: plexSettings };
|
||||||
|
const http: Http = {
|
||||||
|
async fetch(url, init) {
|
||||||
|
const method = init?.method ?? "GET";
|
||||||
|
const body = init?.body ? (JSON.parse(init.body) as unknown) : undefined;
|
||||||
|
calls.push({ method, url, body });
|
||||||
|
const reply = (status: number, value?: unknown) => ({
|
||||||
|
status,
|
||||||
|
text: async () => (value === undefined ? "" : JSON.stringify(value)),
|
||||||
|
});
|
||||||
|
const u = new URL(url);
|
||||||
|
// Other servers an entry may name: a friend's, and plex's own public name (the same server).
|
||||||
|
if (u.hostname === "10.0.0.9") return reply(200, { MediaContainer: { machineIdentifier: "another-server" } });
|
||||||
|
if (u.hostname === "gone.example") throw new Error("getaddrinfo ENOTFOUND");
|
||||||
|
if (u.hostname === "plex.zurag.be") {
|
||||||
|
if (u.pathname === "/identity") return reply(200, { MediaContainer: { machineIdentifier: MACHINE } });
|
||||||
|
return reply(401);
|
||||||
|
}
|
||||||
|
if (u.port === "32400" || u.hostname === "ace.internal") {
|
||||||
|
if (opts.reachable === false) throw new Error("connect ECONNREFUSED");
|
||||||
|
if (u.pathname === "/identity") return reply(200, { MediaContainer: { machineIdentifier: MACHINE } });
|
||||||
|
const token = init?.headers?.["X-Plex-Token"];
|
||||||
|
if (token !== TOKEN) return reply(opts.trusted ? 400 : 401);
|
||||||
|
return reply(200, { MediaContainer: { friendlyName: "ace", machineIdentifier: MACHINE } });
|
||||||
|
}
|
||||||
|
if (init?.headers?.ApiKey !== "ombi-key") return reply(401);
|
||||||
|
if (u.pathname === "/api/v1/Settings/Plex" && method === "GET") return reply(200, store.plex);
|
||||||
|
if (u.pathname === "/api/v1/Settings/Plex" && method === "POST") {
|
||||||
|
store.plex = body as Record<string, unknown>;
|
||||||
|
return reply(200, true);
|
||||||
|
}
|
||||||
|
if (u.pathname === "/api/v1/Tester/plex") {
|
||||||
|
const tried = body as { plexAuthToken?: string; ip?: string };
|
||||||
|
return reply(200, tried.plexAuthToken === TOKEN && tried.ip === "ace.internal");
|
||||||
|
}
|
||||||
|
return reply(404);
|
||||||
|
},
|
||||||
|
};
|
||||||
|
return { http, calls, store };
|
||||||
|
}
|
||||||
|
|
||||||
|
// What an operator's ombi holds: plex loaded through its public name, plus a friend's server.
|
||||||
|
const operatorPlex = () => ({
|
||||||
|
enable: true,
|
||||||
|
enableWatchlistImport: true,
|
||||||
|
monitorAll: false,
|
||||||
|
installId: "b358a2a2-2ab0-4025-a3f3-450313c3c418",
|
||||||
|
servers: [
|
||||||
|
{
|
||||||
|
name: "ace", plexAuthToken: TOKEN, machineIdentifier: MACHINE, episodeBatchSize: 150,
|
||||||
|
serverHostname: "https://app.plex.tv", plexSelectedLibraries: [{ key: "1", title: "Films", enabled: true }],
|
||||||
|
ssl: true, subDir: null, ip: "plex.zurag.be", port: 443, id: 1,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "a friend", plexAuthToken: "their-token", machineIdentifier: "another-server", episodeBatchSize: 150,
|
||||||
|
plexSelectedLibraries: [], ssl: false, subDir: null, ip: "10.0.0.9", port: 32400, id: 2,
|
||||||
|
},
|
||||||
|
],
|
||||||
|
id: 4,
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the server's own entry gets the bound connection; its libraries and every other setting stay", async () => {
|
||||||
|
const f = fakes(operatorPlex());
|
||||||
|
const out = await reconcilePlex(f.http, OMBI, binding(), `${TOKEN}\n`);
|
||||||
|
assert.deepEqual(out, { app: "plex", result: "written", fields: ["ip", "port", "ssl"] });
|
||||||
|
const want = operatorPlex();
|
||||||
|
Object.assign(want.servers[0], { ip: "ace.internal", port: 32400, ssl: false });
|
||||||
|
assert.deepEqual(f.store.plex, want);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("another server's entry is never touched", async () => {
|
||||||
|
const f = fakes(operatorPlex());
|
||||||
|
await reconcilePlex(f.http, OMBI, binding(), TOKEN);
|
||||||
|
const servers = f.store.plex.servers as Record<string, unknown>[];
|
||||||
|
assert.deepEqual(servers[1], operatorPlex().servers[1]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("nothing is written when ombi already says what the mesh says", async () => {
|
||||||
|
const doc = operatorPlex();
|
||||||
|
Object.assign(doc.servers[0], { ip: "ace.internal", port: 32400, ssl: false });
|
||||||
|
const f = fakes(doc);
|
||||||
|
const out = await reconcilePlex(f.http, OMBI, binding(), TOKEN);
|
||||||
|
assert.deepEqual(out, { app: "plex", result: "unchanged" });
|
||||||
|
assert.equal(f.calls.filter((c) => c.method === "POST" && c.url.includes("/Settings/")).length, 0);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("an ombi with no entry for this server gets one, named as plex names itself", async () => {
|
||||||
|
const fresh = { enable: false, enableWatchlistImport: false, monitorAll: false, installId: "x", servers: null, id: 0 };
|
||||||
|
const f = fakes(fresh);
|
||||||
|
const out = await reconcilePlex(f.http, OMBI, binding(), TOKEN);
|
||||||
|
assert.deepEqual(out, { app: "plex", result: "written", fields: ["server"] });
|
||||||
|
assert.deepEqual(f.store.plex, {
|
||||||
|
...fresh,
|
||||||
|
servers: [{
|
||||||
|
name: "ace", machineIdentifier: MACHINE, ip: "ace.internal", port: 32400, ssl: false, subDir: null,
|
||||||
|
plexAuthToken: TOKEN, episodeBatchSize: 150, plexSelectedLibraries: [],
|
||||||
|
}],
|
||||||
|
});
|
||||||
|
assert.equal(f.store.plex.enable, false, "whether plex is enabled in ombi is the operator's choice");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a token plex refuses is never written, and the accept that fixes it is named", async () => {
|
||||||
|
for (const trusted of [false, true]) {
|
||||||
|
const f = fakes(operatorPlex(), { trusted });
|
||||||
|
const out = await reconcilePlex(f.http, OMBI, binding(), "a-value-the-mesh-minted");
|
||||||
|
assert.equal(out.result, "refused");
|
||||||
|
const problem = (out as { problem: string }).problem;
|
||||||
|
assert.match(problem, /secret accept <this node> ombi plex-api --provider ace/);
|
||||||
|
assert.doesNotMatch(problem, /a-value-the-mesh-minted/);
|
||||||
|
assert.deepEqual(f.store.plex, operatorPlex(), "ombi's working settings were left alone");
|
||||||
|
assert.equal(f.calls.some((c) => c.url.includes("/api/v1/")), false, "ombi was not even asked");
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a plex it cannot reach is reported, and ombi is left alone", async () => {
|
||||||
|
const f = fakes(operatorPlex(), { reachable: false });
|
||||||
|
const out = await reconcilePlex(f.http, OMBI, binding(), TOKEN);
|
||||||
|
assert.equal(out.result, "refused");
|
||||||
|
assert.match((out as { problem: string }).problem, /could not be asked.*ECONNREFUSED/);
|
||||||
|
assert.deepEqual(f.store.plex, operatorPlex());
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a loopback binding is refused: from ombi's container it is ombi itself", () => {
|
||||||
|
const w = wantedPlex(binding(32400, "127.0.0.1"), TOKEN);
|
||||||
|
assert.equal(w.ok, false);
|
||||||
|
assert.match((w as { problem: string }).problem, /private network/);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("an https binding sets ombi's ssl flag; an empty subDir is none", () => {
|
||||||
|
const w = wantedPlex(binding(32400, "ace.internal", "https"), TOKEN);
|
||||||
|
assert.equal(w.ok && w.connection.ssl, true);
|
||||||
|
assert.deepEqual(
|
||||||
|
differingPlex({ ip: "h", port: 1, ssl: false, subDir: "", plexAuthToken: "k" }, { ip: "h", port: 1, ssl: false, subDir: null, plexAuthToken: "k" }),
|
||||||
|
[],
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("every entry naming the server is laid over, not only the first", () => {
|
||||||
|
const doc = { servers: [{ machineIdentifier: MACHINE, ip: "a" }, { machineIdentifier: MACHINE, ip: "b" }] };
|
||||||
|
const want = { ip: "ace.internal", port: 32400, ssl: false, subDir: null, plexAuthToken: TOKEN };
|
||||||
|
const laid = withPlexServer(doc, MACHINE, want, "ace");
|
||||||
|
assert.equal(laid.added, false);
|
||||||
|
assert.deepEqual((laid.next.servers as { ip: string }[]).map((s) => s.ip), ["ace.internal", "ace.internal"]);
|
||||||
|
});
|
||||||
|
|
||||||
|
// ace's own ombi: its one entry was loaded from an older server (a stale identifier) and retyped to
|
||||||
|
// plex's public name, so it IS this server, reached another way (read from ace, 2026-09-30).
|
||||||
|
const acesOmbi = () => ({
|
||||||
|
enable: true,
|
||||||
|
enableWatchlistImport: true,
|
||||||
|
servers: [{
|
||||||
|
name: "Nami", plexAuthToken: TOKEN, machineIdentifier: "76562198623e708eef85b46aedb72c8f2fe671aa", episodeBatchSize: 0,
|
||||||
|
plexSelectedLibraries: [1, 2, 3, 4, 5, 6].map((k) => ({ key: String(k), enabled: true })), ssl: true, subDir: null,
|
||||||
|
ip: "plex.zurag.be", port: 443, id: 1,
|
||||||
|
}],
|
||||||
|
id: 4,
|
||||||
|
});
|
||||||
|
|
||||||
|
test("an entry whose own address answers as this server is adopted: connection and identifier, nothing else", async () => {
|
||||||
|
const f = fakes(acesOmbi());
|
||||||
|
const out = await reconcilePlex(f.http, OMBI, binding(), TOKEN);
|
||||||
|
assert.deepEqual(out, { app: "plex", result: "written", fields: ["ip", "port", "ssl", "machineIdentifier"] });
|
||||||
|
const want = acesOmbi();
|
||||||
|
Object.assign(want.servers[0], { ip: "ace.internal", port: 32400, ssl: false, machineIdentifier: MACHINE });
|
||||||
|
assert.deepEqual(f.store.plex, want, "one entry, still named Nami, its six libraries kept; none added");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("an entry answering as another server, or not at all, is not adopted; this server gets its own", async () => {
|
||||||
|
const doc = {
|
||||||
|
servers: [
|
||||||
|
{ name: "a friend", machineIdentifier: "stale-1", ip: "10.0.0.9", port: 32400, ssl: false, plexAuthToken: "theirs" },
|
||||||
|
{ name: "gone", machineIdentifier: "stale-2", ip: "gone.example", port: 32400, ssl: false, plexAuthToken: "old" },
|
||||||
|
],
|
||||||
|
};
|
||||||
|
const f = fakes(structuredClone(doc));
|
||||||
|
const out = await reconcilePlex(f.http, OMBI, binding(), TOKEN);
|
||||||
|
assert.deepEqual(out, { app: "plex", result: "written", fields: ["server"] });
|
||||||
|
const servers = f.store.plex.servers as Record<string, unknown>[];
|
||||||
|
assert.deepEqual(servers.slice(0, 2), doc.servers, "both left exactly as they were");
|
||||||
|
assert.equal(servers[2].machineIdentifier, MACHINE);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("no entry is probed once one carries the server's identifier", async () => {
|
||||||
|
const f = fakes(operatorPlex());
|
||||||
|
await reconcilePlex(f.http, OMBI, binding(), TOKEN);
|
||||||
|
assert.equal(f.calls.some((c) => c.url.startsWith("http://10.0.0.9")), false, "the friend's server was not asked");
|
||||||
|
});
|
||||||
@@ -0,0 +1,147 @@
|
|||||||
|
// What holds ombi's Servarr step (servarr/settings.ts): the connection ombi keeps for each app is
|
||||||
|
// made to say what the mesh bound — host, port, TLS, base path, key — and nothing else it keeps is
|
||||||
|
// touched; nothing is written when nothing differs; Radarr's 4K instance is left alone; and a key the
|
||||||
|
// app refuses (the mesh's own minted value, before the operator accepts the app's key) is never
|
||||||
|
// written, with the `secret accept` that fixes it named.
|
||||||
|
//
|
||||||
|
// ombi and the apps are fakes: the routes the step touches, answering as the real ones do (checked
|
||||||
|
// against lscr.io/linuxserver/ombi 4.53.10 and the catalogue's pinned sonarr/radarr/lidarr).
|
||||||
|
|
||||||
|
import { test } from "node:test";
|
||||||
|
import assert from "node:assert/strict";
|
||||||
|
|
||||||
|
import { APPS, differing, reconcileApp, subDirOf, wanted, type Binding, type Http, type ServarrApp } from "../servarr/settings.ts";
|
||||||
|
|
||||||
|
const SONARR = APPS.find((a) => a.app === "sonarr") as ServarrApp;
|
||||||
|
const RADARR = APPS.find((a) => a.app === "radarr") as ServarrApp;
|
||||||
|
const LIDARR = APPS.find((a) => a.app === "lidarr") as ServarrApp;
|
||||||
|
const THE_KEY = "the-apps-own-key";
|
||||||
|
|
||||||
|
function binding(provision: string, port: number, at = "ace.internal"): Binding {
|
||||||
|
return { binding: 1, provision, from: "ace", at, as: "mesh_ace_ombi", serves: { scheme: "http", port, "url-base": "" } } as Binding;
|
||||||
|
}
|
||||||
|
|
||||||
|
interface Call {
|
||||||
|
method: string;
|
||||||
|
url: string;
|
||||||
|
body?: unknown;
|
||||||
|
}
|
||||||
|
|
||||||
|
/** ombi's settings store and the apps' key check, behind one fetch. */
|
||||||
|
function fakes(settings: Record<string, unknown>, opts: { appKey?: string; reachable?: boolean } = {}) {
|
||||||
|
const calls: Call[] = [];
|
||||||
|
const appKey = opts.appKey ?? THE_KEY;
|
||||||
|
const http: Http = {
|
||||||
|
async fetch(url, init) {
|
||||||
|
const method = init?.method ?? "GET";
|
||||||
|
const body = init?.body ? (JSON.parse(init.body) as unknown) : undefined;
|
||||||
|
calls.push({ method, url, body });
|
||||||
|
const reply = (status: number, value?: unknown) => ({
|
||||||
|
status,
|
||||||
|
text: async () => (value === undefined ? "" : JSON.stringify(value)),
|
||||||
|
});
|
||||||
|
const u = new URL(url);
|
||||||
|
if (u.pathname.endsWith("/system/status")) {
|
||||||
|
if (opts.reachable === false) throw new Error("connect ECONNREFUSED");
|
||||||
|
return init?.headers?.["X-Api-Key"] === appKey ? reply(200, { version: "4" }) : reply(401);
|
||||||
|
}
|
||||||
|
if (init?.headers?.ApiKey !== "ombi-key") return reply(401);
|
||||||
|
const m = u.pathname.match(/^\/api\/v1\/(Settings|Tester)\/(\w+)$/);
|
||||||
|
if (!m) return reply(404);
|
||||||
|
const [, kind, app] = m;
|
||||||
|
if (kind === "Settings" && method === "GET") return reply(200, settings[app]);
|
||||||
|
if (kind === "Settings" && method === "POST") {
|
||||||
|
settings[app] = body;
|
||||||
|
return reply(200, true);
|
||||||
|
}
|
||||||
|
const tried = body as { apiKey?: string };
|
||||||
|
return reply(200, { isValid: tried.apiKey === appKey, expectedSubDir: null });
|
||||||
|
},
|
||||||
|
};
|
||||||
|
return { http, calls, settings };
|
||||||
|
}
|
||||||
|
|
||||||
|
const OMBI = { url: "http://127.0.0.1:3579", apiKey: "ombi-key" };
|
||||||
|
|
||||||
|
const operatorSonarr = () => ({
|
||||||
|
enabled: true, apiKey: "old-key", qualityProfile: "3", seasonFolders: true, rootPath: "10",
|
||||||
|
qualityProfileAnime: "7", rootPathAnime: "9", languageProfile: 1, ssl: false, subDir: null,
|
||||||
|
ip: "sonarr", port: 8989, id: 5,
|
||||||
|
});
|
||||||
|
|
||||||
|
test("it writes the connection the mesh bound, and keeps every other setting ombi had", async () => {
|
||||||
|
const f = fakes({ sonarr: operatorSonarr() });
|
||||||
|
const out = await reconcileApp(f.http, OMBI, SONARR, binding("sonarr-api", 20101), `${THE_KEY}\n`);
|
||||||
|
assert.deepEqual(out, { app: "sonarr", result: "written", fields: ["ip", "port", "apiKey"] });
|
||||||
|
assert.deepEqual(f.settings.sonarr, {
|
||||||
|
...operatorSonarr(), ip: "ace.internal", port: 20101, apiKey: THE_KEY, ssl: false, subDir: null,
|
||||||
|
});
|
||||||
|
// Checked against the app itself, at the bound address, before anything was written.
|
||||||
|
assert.equal(f.calls[0].url, "http://ace.internal:20101/api/v3/system/status");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("nothing is written when ombi already says what the mesh says", async () => {
|
||||||
|
const f = fakes({ sonarr: { ...operatorSonarr(), ip: "ace.internal", port: 20101, apiKey: THE_KEY } });
|
||||||
|
const out = await reconcileApp(f.http, OMBI, SONARR, binding("sonarr-api", 20101), THE_KEY);
|
||||||
|
assert.deepEqual(out, { app: "sonarr", result: "unchanged" });
|
||||||
|
assert.equal(f.calls.filter((c) => c.method === "POST" && c.url.includes("/Settings/")).length, 0);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a key the app refuses is never written, and the accept that fixes it is named", async () => {
|
||||||
|
const f = fakes({ sonarr: operatorSonarr() });
|
||||||
|
const out = await reconcileApp(f.http, OMBI, SONARR, binding("sonarr-api", 20101), "a-value-the-mesh-minted");
|
||||||
|
assert.equal(out.result, "refused");
|
||||||
|
assert.match((out as { problem: string }).problem, /secret accept <this node> ombi sonarr-api --provider ace/);
|
||||||
|
assert.doesNotMatch((out as { problem: string }).problem, /a-value-the-mesh-minted/);
|
||||||
|
assert.deepEqual(f.settings.sonarr, operatorSonarr(), "ombi's working settings were left alone");
|
||||||
|
assert.equal(f.calls.some((c) => c.url.includes("/api/v1/")), false, "ombi was not even asked");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("an app it cannot reach is reported, and ombi is left alone", async () => {
|
||||||
|
const f = fakes({ sonarr: operatorSonarr() }, { reachable: false });
|
||||||
|
const out = await reconcileApp(f.http, OMBI, SONARR, binding("sonarr-api", 20101), THE_KEY);
|
||||||
|
assert.equal(out.result, "refused");
|
||||||
|
assert.match((out as { problem: string }).problem, /could not be asked.*ECONNREFUSED/);
|
||||||
|
assert.deepEqual(f.settings.sonarr, operatorSonarr());
|
||||||
|
});
|
||||||
|
|
||||||
|
test("radarr's connection is written inside its combined document, and the 4K instance is untouched", async () => {
|
||||||
|
const fourK = { enabled: true, apiKey: "4k-key", ip: "radarr4k", port: 7879, defaultQualityProfile: "9", id: 7 };
|
||||||
|
const f = fakes({ radarr: { radarr: { enabled: true, apiKey: "old", ip: "radarr", port: 7878, defaultRootPath: "/movies", id: 6 }, radarr4K: fourK } });
|
||||||
|
const out = await reconcileApp(f.http, OMBI, RADARR, binding("radarr-api", 20102), THE_KEY);
|
||||||
|
assert.equal(out.result, "written");
|
||||||
|
const doc = f.settings.radarr as { radarr: Record<string, unknown>; radarr4K: unknown };
|
||||||
|
assert.deepEqual(doc.radarr4K, fourK);
|
||||||
|
assert.equal(doc.radarr.ip, "ace.internal");
|
||||||
|
assert.equal(doc.radarr.port, 20102);
|
||||||
|
assert.equal(doc.radarr.defaultRootPath, "/movies");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("lidarr is checked on its own API version", async () => {
|
||||||
|
const f = fakes({ lidarr: { enabled: true, apiKey: null, ip: null, port: 0, id: 0 } });
|
||||||
|
const out = await reconcileApp(f.http, OMBI, LIDARR, binding("lidarr-api", 20103), THE_KEY);
|
||||||
|
assert.equal(out.result, "written");
|
||||||
|
assert.equal(f.calls[0].url, "http://ace.internal:20103/api/v1/system/status");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("a loopback binding is refused: from ombi's container it is ombi itself", () => {
|
||||||
|
const w = wanted(SONARR, binding("sonarr-api", 20101, "127.0.0.1"), THE_KEY);
|
||||||
|
assert.equal(w.ok, false);
|
||||||
|
assert.match((w as { problem: string }).problem, /private network/);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("the base path is ombi's subDir, slashes trimmed; empty is none", () => {
|
||||||
|
assert.equal(subDirOf(""), null);
|
||||||
|
assert.equal(subDirOf("/sonarr/"), "sonarr");
|
||||||
|
assert.deepEqual(
|
||||||
|
differing({ ip: "h", port: 1, ssl: false, subDir: "", apiKey: "k" }, { ip: "h", port: 1, ssl: false, subDir: null, apiKey: "k" }),
|
||||||
|
[],
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("an https binding sets ombi's ssl flag", () => {
|
||||||
|
const b = binding("sonarr-api", 443);
|
||||||
|
(b.serves as Record<string, unknown>).scheme = "https";
|
||||||
|
const w = wanted(SONARR, b, THE_KEY);
|
||||||
|
assert.equal(w.ok && w.connection.ssl, true);
|
||||||
|
});
|
||||||
@@ -8,5 +8,5 @@
|
|||||||
"skipLibCheck": true,
|
"skipLibCheck": true,
|
||||||
"noEmit": true
|
"noEmit": true
|
||||||
},
|
},
|
||||||
"include": ["client.ts", "index.ts", "tools/index.ts"]
|
"include": ["client.ts", "index.ts", "tools/index.ts", "servarr/settings.ts", "plex/settings.ts", "connections/index.ts"]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -11,7 +11,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "office",
|
"label": "office",
|
||||||
"port": 9070
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
@@ -22,6 +22,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 9070,
|
"port": 9070,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -11,7 +11,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "eef",
|
"label": "eef",
|
||||||
"port": 4012
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
@@ -19,6 +19,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 4012,
|
"port": 4012,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -11,7 +11,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "filip",
|
"label": "filip",
|
||||||
"port": 4013
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
@@ -19,6 +19,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 4013,
|
"port": 4013,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -18,7 +18,7 @@
|
|||||||
},
|
},
|
||||||
"route": {
|
"route": {
|
||||||
"label": "photos",
|
"label": "photos",
|
||||||
"port": 4001
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
@@ -32,12 +32,14 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "api",
|
||||||
"port": 9000,
|
"port": 9000,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "the photos backend API; the client sites on the module network call it"
|
"why": "the photos backend API; the client sites on the module network call it"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 4001,
|
"port": 4001,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -18,6 +18,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "stream",
|
||||||
"port": 32400,
|
"port": 32400,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -7,12 +7,14 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 9090,
|
"port": 9090,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "the dashboard over http; portainer.novox.be is a route grant and the proxy reaches it here \u2014 the machine side of 9090:9000, the predecessor's number"
|
"why": "the dashboard over http; portainer.novox.be is a route grant and the proxy reaches it here \u2014 the machine side of 9090:9000, the predecessor's number"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "web-tls",
|
||||||
"port": 9443,
|
"port": 9443,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
@@ -103,7 +105,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "portainer",
|
"label": "portainer",
|
||||||
"port": 9090
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
|
|||||||
@@ -26,6 +26,7 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "database",
|
||||||
"port": 5432,
|
"port": 5432,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -16,6 +16,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 8080,
|
"port": 8080,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
@@ -81,7 +82,7 @@
|
|||||||
],
|
],
|
||||||
"env": {
|
"env": {
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||||
"MESH_QBITTORRENT_URL": "http://127.0.0.1:8080",
|
"MESH_QBITTORRENT_URL": "http://127.0.0.1:${port:8080}",
|
||||||
"MESH_QBITTORRENT_PASSWORD_FILE": "/run/secrets/password",
|
"MESH_QBITTORRENT_PASSWORD_FILE": "/run/secrets/password",
|
||||||
"MESH_QBITTORRENT_CONFIG_FILE": "/run/config/config.json",
|
"MESH_QBITTORRENT_CONFIG_FILE": "/run/config/config.json",
|
||||||
"MESH_QBITTORRENT_CONFIG_DIR": "/var/lib/qbittorrent/config"
|
"MESH_QBITTORRENT_CONFIG_DIR": "/var/lib/qbittorrent/config"
|
||||||
|
|||||||
@@ -1,6 +1,19 @@
|
|||||||
{
|
{
|
||||||
"module": "radarr",
|
"module": "radarr",
|
||||||
"version": "1",
|
"version": "1",
|
||||||
|
"provides": [
|
||||||
|
{
|
||||||
|
"name": "radarr-api",
|
||||||
|
"scope": "mesh"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"serves": {
|
||||||
|
"radarr-api": {
|
||||||
|
"scheme": "http",
|
||||||
|
"port": 7878,
|
||||||
|
"url-base": ""
|
||||||
|
}
|
||||||
|
},
|
||||||
"capabilities": [
|
"capabilities": [
|
||||||
"container-runtime"
|
"container-runtime"
|
||||||
],
|
],
|
||||||
@@ -14,6 +27,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 7878,
|
"port": 7878,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
@@ -74,7 +88,7 @@
|
|||||||
],
|
],
|
||||||
"env": {
|
"env": {
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||||
"MESH_RADARR_URL": "http://127.0.0.1:7878",
|
"MESH_RADARR_URL": "http://127.0.0.1:${port:7878}",
|
||||||
"MESH_RADARR_CONFIG_DIR": "/var/lib/radarr/config"
|
"MESH_RADARR_CONFIG_DIR": "/var/lib/radarr/config"
|
||||||
},
|
},
|
||||||
"artifact": "runtime"
|
"artifact": "runtime"
|
||||||
@@ -86,7 +100,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "movies",
|
"label": "movies",
|
||||||
"port": 7878
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
|
|||||||
@@ -40,6 +40,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "cache",
|
||||||
"port": 6379,
|
"port": 6379,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -27,12 +27,14 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "http",
|
||||||
"port": 80,
|
"port": 80,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "anywhere",
|
"from": "anywhere",
|
||||||
"why": "public HTTP, and the ACME HTTP-01 challenge answered at the name being certified"
|
"why": "public HTTP, and the ACME HTTP-01 challenge answered at the name being certified"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "https",
|
||||||
"port": 443,
|
"port": 443,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "anywhere",
|
"from": "anywhere",
|
||||||
|
|||||||
+24
-22
@@ -5,11 +5,12 @@
|
|||||||
"container-runtime"
|
"container-runtime"
|
||||||
],
|
],
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"secret": "/var/lib/searxng-module/secret.secret",
|
"secret": "/var/lib/mesh/searxng/secret",
|
||||||
"broker": "/var/lib/mesh/searxng/broker"
|
"broker": "/var/lib/mesh/searxng/broker"
|
||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 8080,
|
"port": 8080,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
@@ -26,22 +27,14 @@
|
|||||||
{
|
{
|
||||||
"id": "state",
|
"id": "state",
|
||||||
"type": "directory",
|
"type": "directory",
|
||||||
"path": "/var/lib/searxng-module",
|
"mode": "0700",
|
||||||
"mode": "0700"
|
"place": "."
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "valkey-data",
|
"id": "valkey-data",
|
||||||
"type": "directory",
|
"type": "directory",
|
||||||
"path": "/var/lib/searxng-module/valkey-data",
|
|
||||||
"mode": "0700"
|
"mode": "0700"
|
||||||
},
|
},
|
||||||
{
|
|
||||||
"id": "server-env",
|
|
||||||
"type": "file",
|
|
||||||
"path": "/var/lib/searxng-module/server.env",
|
|
||||||
"mode": "0600",
|
|
||||||
"content": "SEARXNG_SECRET=${secret:secret}\nSEARXNG_VALKEY_URL=valkey://valkey:6379/0\n"
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
"id": "net",
|
"id": "net",
|
||||||
"type": "network",
|
"type": "network",
|
||||||
@@ -62,30 +55,39 @@
|
|||||||
"warning"
|
"warning"
|
||||||
],
|
],
|
||||||
"volumes": [
|
"volumes": [
|
||||||
"/var/lib/searxng-module/valkey-data:/data"
|
"${dir:valkey-data}:/data"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
"id": "settings",
|
||||||
|
"type": "file",
|
||||||
|
"path": "${dir:state}/settings.yml",
|
||||||
|
"mode": "0600",
|
||||||
|
"merge": "json",
|
||||||
|
"content": "{\n \"use_default_settings\": true,\n \"server\": {\n \"secret_key\": \"${secret:secret}\",\n \"base_url\": false,\n \"limiter\": false,\n \"image_proxy\": false,\n \"public_instance\": false\n },\n \"search\": {\n \"formats\": [\"html\", \"json\"]\n },\n \"valkey\": {\n \"url\": \"valkey://valkey:6379/0\"\n }\n}\n"
|
||||||
|
},
|
||||||
{
|
{
|
||||||
"id": "server",
|
"id": "server",
|
||||||
"type": "container",
|
"type": "container",
|
||||||
"name": "searxng",
|
"name": "searxng",
|
||||||
"image": "searxng/searxng@sha256:c7cc75852051bf6254afda6ed1b920dd1677d8efe4ab141bf558f02e582f4371",
|
"image": "searxng/searxng@sha256:cd8812607ab73730a0b1a0dc4990223fe1b9e383f6f35947114d0bef7f8bb441",
|
||||||
"network": "searxng",
|
"network": "searxng",
|
||||||
"env-file": [
|
|
||||||
"/var/lib/searxng-module/server.env"
|
|
||||||
],
|
|
||||||
"ports": [
|
"ports": [
|
||||||
"8080"
|
"8080"
|
||||||
],
|
],
|
||||||
"secrets-in-environment": "SEARXNG_SECRET is env-only, but settings.yml carries server.secret_key; convertible by mounting a generated settings.yml, not yet done"
|
"volumes": [
|
||||||
|
"${dir:state}/settings.yml:/etc/searxng/settings.yml:ro"
|
||||||
|
],
|
||||||
|
"restart-on": [
|
||||||
|
"settings"
|
||||||
|
]
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "runtime-config",
|
"id": "runtime-config",
|
||||||
"type": "file",
|
"type": "file",
|
||||||
"path": "/var/lib/mesh/searxng/config.json",
|
"path": "/var/lib/mesh/searxng/config.json",
|
||||||
"mode": "0600",
|
"mode": "0600",
|
||||||
"content": "{}\n",
|
"content": "{}\n"
|
||||||
"merge": "json"
|
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "runtime",
|
"id": "runtime",
|
||||||
@@ -98,7 +100,7 @@
|
|||||||
],
|
],
|
||||||
"env": {
|
"env": {
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||||
"MESH_SEARXNG_URL": "http://127.0.0.1:8080",
|
"MESH_SEARXNG_URL": "http://127.0.0.1:${port:8080}",
|
||||||
"MESH_SEARXNG_CONFIG_FILE": "/run/config/config.json"
|
"MESH_SEARXNG_CONFIG_FILE": "/run/config/config.json"
|
||||||
},
|
},
|
||||||
"restart-on": [
|
"restart-on": [
|
||||||
@@ -113,11 +115,11 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "searxng",
|
"label": "searxng",
|
||||||
"port": 8080
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
"route": "/var/lib/searxng-module/route.json"
|
"route": "${dir:state}/route.json"
|
||||||
},
|
},
|
||||||
"build": {
|
"build": {
|
||||||
"on": [
|
"on": [
|
||||||
|
|||||||
@@ -43,6 +43,7 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 8080,
|
"port": 8080,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -1,6 +1,19 @@
|
|||||||
{
|
{
|
||||||
"module": "sonarr",
|
"module": "sonarr",
|
||||||
"version": "1",
|
"version": "1",
|
||||||
|
"provides": [
|
||||||
|
{
|
||||||
|
"name": "sonarr-api",
|
||||||
|
"scope": "mesh"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"serves": {
|
||||||
|
"sonarr-api": {
|
||||||
|
"scheme": "http",
|
||||||
|
"port": 8989,
|
||||||
|
"url-base": ""
|
||||||
|
}
|
||||||
|
},
|
||||||
"capabilities": [
|
"capabilities": [
|
||||||
"container-runtime"
|
"container-runtime"
|
||||||
],
|
],
|
||||||
@@ -14,6 +27,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 8989,
|
"port": 8989,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
@@ -79,7 +93,7 @@
|
|||||||
],
|
],
|
||||||
"env": {
|
"env": {
|
||||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||||
"MESH_SONARR_URL": "http://127.0.0.1:8989",
|
"MESH_SONARR_URL": "http://127.0.0.1:${port:8989}",
|
||||||
"MESH_SONARR_CONFIG_DIR": "/var/lib/sonarr/config"
|
"MESH_SONARR_CONFIG_DIR": "/var/lib/sonarr/config"
|
||||||
},
|
},
|
||||||
"artifact": "runtime"
|
"artifact": "runtime"
|
||||||
@@ -91,7 +105,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "series",
|
"label": "series",
|
||||||
"port": 8989
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
|
|||||||
@@ -7,6 +7,7 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "ssh",
|
||||||
"port": 22,
|
"port": 22,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "anywhere",
|
"from": "anywhere",
|
||||||
@@ -31,6 +32,7 @@
|
|||||||
"type": "service",
|
"type": "service",
|
||||||
"unit": "sshd.service",
|
"unit": "sshd.service",
|
||||||
"state": "running",
|
"state": "running",
|
||||||
|
"boot": "enabled",
|
||||||
"restart-on": [
|
"restart-on": [
|
||||||
"config"
|
"config"
|
||||||
]
|
]
|
||||||
|
|||||||
@@ -26,6 +26,7 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "acme",
|
||||||
"port": 9000,
|
"port": 9000,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
@@ -12,6 +12,7 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 8181,
|
"port": 8181,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
@@ -85,7 +86,7 @@
|
|||||||
"contributes": {
|
"contributes": {
|
||||||
"route": {
|
"route": {
|
||||||
"label": "tautulli",
|
"label": "tautulli",
|
||||||
"port": 8181
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
|
|||||||
@@ -15,7 +15,7 @@
|
|||||||
},
|
},
|
||||||
"route": {
|
"route": {
|
||||||
"label": "umami",
|
"label": "umami",
|
||||||
"port": 3000
|
"endpoint": "web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"binds": {
|
"binds": {
|
||||||
@@ -49,10 +49,11 @@
|
|||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 3000,
|
"port": 3000,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "anywhere",
|
"from": "mesh",
|
||||||
"why": "one port serves two surfaces: the dashboard (the proxy gates it to the mesh) and the public collection endpoint that the browsers of every tracked site POST to \u2014 so the port itself must be reachable from anywhere"
|
"why": "one port serves two surfaces \u2014 the dashboard and the collection endpoint that the browsers of every tracked site POST to. Both are reached through the proxy, by name, so the port is how the proxy reaches this module and nothing else (novox/hq ADR 0045). It said \"anywhere\" and gave the reason that the collection endpoint must be public, which is true of the name and not of the port: opened, the machine-side port served the dashboard over plain HTTP to the internet, bypassing every rule the proxy applies by path"
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"resources": [
|
"resources": [
|
||||||
|
|||||||
@@ -6,54 +6,63 @@
|
|||||||
],
|
],
|
||||||
"listens": [
|
"listens": [
|
||||||
{
|
{
|
||||||
|
"name": "web",
|
||||||
"port": 8443,
|
"port": 8443,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "the controller web UI, over its own self-signed tls; reaching it from outside is a route grant later"
|
"why": "the controller web UI, over its own self-signed tls; reaching it from outside is a route grant later"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "inform",
|
||||||
"port": 8080,
|
"port": 8080,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "device inform \u2014 how APs and switches check in and are adopted"
|
"why": "device inform \u2014 how APs and switches check in and are adopted"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "stun",
|
||||||
"port": 3478,
|
"port": 3478,
|
||||||
"protocol": "udp",
|
"protocol": "udp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "STUN, so managed devices can find the controller through NAT"
|
"why": "STUN, so managed devices can find the controller through NAT"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "discovery",
|
||||||
"port": 10001,
|
"port": 10001,
|
||||||
"protocol": "udp",
|
"protocol": "udp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "device discovery \u2014 the controller finds unadopted devices on the network"
|
"why": "device discovery \u2014 the controller finds unadopted devices on the network"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "discovery-l2",
|
||||||
"port": 1902,
|
"port": 1902,
|
||||||
"protocol": "udp",
|
"protocol": "udp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "layer-2 (UBNT) discovery broadcasts; published on 1902, the container listens on 1900"
|
"why": "layer-2 (UBNT) discovery broadcasts; published on 1902, the container listens on 1900"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "portal-tls",
|
||||||
"port": 8843,
|
"port": 8843,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "the guest captive portal over https"
|
"why": "the guest captive portal over https"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "portal",
|
||||||
"port": 8880,
|
"port": 8880,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "the guest captive portal over http"
|
"why": "the guest captive portal over http"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "speedtest",
|
||||||
"port": 6789,
|
"port": 6789,
|
||||||
"protocol": "tcp",
|
"protocol": "tcp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
"why": "mobile-app speed-test throughput measurement"
|
"why": "mobile-app speed-test throughput measurement"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"name": "syslog",
|
||||||
"port": 5514,
|
"port": 5514,
|
||||||
"protocol": "udp",
|
"protocol": "udp",
|
||||||
"from": "mesh",
|
"from": "mesh",
|
||||||
|
|||||||
Reference in New Issue
Block a user