Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
8dcdd45660 |
+22
-47
@@ -1,26 +1,6 @@
|
||||
{
|
||||
"module": "icecast",
|
||||
"version": "1",
|
||||
"requires": [
|
||||
"route",
|
||||
"secret"
|
||||
],
|
||||
"contributes": {
|
||||
"route": {
|
||||
"label": "icecast",
|
||||
"endpoint": "stream"
|
||||
}
|
||||
},
|
||||
"binds": {
|
||||
"route": "${dir:state}/route.json"
|
||||
},
|
||||
"secrets": {
|
||||
"secret": {
|
||||
"source": "${dir:state}/source.secret",
|
||||
"admin": "${dir:state}/admin.secret",
|
||||
"relay": "${dir:state}/relay.secret"
|
||||
}
|
||||
},
|
||||
"capabilities": [
|
||||
"container-runtime"
|
||||
],
|
||||
@@ -37,7 +17,7 @@
|
||||
"port": 8000,
|
||||
"protocol": "tcp",
|
||||
"from": "mesh",
|
||||
"why": "streams in from sources (HTTP PUT) and out to listeners, plus the status and admin pages; a public name is its route"
|
||||
"why": "streams in from sources and out to listeners"
|
||||
}
|
||||
],
|
||||
"resources": [
|
||||
@@ -50,43 +30,28 @@
|
||||
{
|
||||
"id": "state",
|
||||
"type": "directory",
|
||||
"mode": "0700",
|
||||
"place": "."
|
||||
"path": "/var/lib/icecast-module",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "logs",
|
||||
"type": "directory",
|
||||
"mode": "0700",
|
||||
"owner": "100:101"
|
||||
},
|
||||
{
|
||||
"id": "server-conf",
|
||||
"id": "server-env",
|
||||
"type": "file",
|
||||
"path": "${dir:state}/icecast.xml",
|
||||
"path": "/var/lib/icecast-module/server.env",
|
||||
"mode": "0600",
|
||||
"content": "<icecast>\n <!-- Written by the mesh (modules/icecast). Passwords arrive as secrets rendered into this file,\n never as environment: the image's entrypoint seds ICECAST_* variables into the file only\n when they are set, and none are. -->\n <location>Earth</location>\n <admin>icemaster@localhost</admin>\n <limits>\n <clients>100</clients>\n <sources>2</sources>\n <queue-size>524288</queue-size>\n <client-timeout>30</client-timeout>\n <header-timeout>15</header-timeout>\n <source-timeout>10</source-timeout>\n <burst-on-connect>1</burst-on-connect>\n <burst-size>65535</burst-size>\n </limits>\n <authentication>\n <source-password>${secret:source}</source-password>\n <relay-password>${secret:relay}</relay-password>\n <admin-user>admin</admin-user>\n <admin-password>${secret:admin}</admin-password>\n </authentication>\n <!-- The name icecast writes into playlists (.m3u/.xspf: http://<hostname>:<port>/<mount>) and\n would announce to YP (none configured). A machine's own name belongs to its assignment, and\n an assignment merges only into JSON; this XML cannot take it, so the neutral default stays. -->\n <hostname>localhost</hostname>\n <listen-socket>\n <port>8000</port>\n </listen-socket>\n <http-headers>\n <header name=\"Access-Control-Allow-Origin\" value=\"*\" />\n </http-headers>\n <fileserve>1</fileserve>\n <paths>\n <basedir>/usr/share/icecast</basedir>\n <logdir>/var/log/icecast</logdir>\n <webroot>/usr/share/icecast/web</webroot>\n <adminroot>/usr/share/icecast/admin</adminroot>\n <alias source=\"/\" destination=\"/status.xsl\"/>\n </paths>\n <logging>\n <accesslog>access.log</accesslog>\n <errorlog>error.log</errorlog>\n <loglevel>3</loglevel>\n <logsize>10000</logsize>\n </logging>\n <security>\n <chroot>0</chroot>\n <!-- Starts as root, reads this 0600 root-owned file, then drops to the image's icecast user\n (uid 100, group icecast 101) before serving. -->\n <changeowner>\n <user>icecast</user>\n <group>icecast</group>\n </changeowner>\n </security>\n</icecast>\n"
|
||||
},
|
||||
{
|
||||
"id": "net",
|
||||
"type": "network",
|
||||
"name": "icecast"
|
||||
"content": "ICECAST_SOURCE_PASSWORD=${secret:source}\nICECAST_ADMIN_PASSWORD=${secret:admin}\nICECAST_RELAY_PASSWORD=${secret:relay}\nICECAST_ADMIN_USERNAME=admin\n"
|
||||
},
|
||||
{
|
||||
"id": "server",
|
||||
"type": "container",
|
||||
"name": "icecast",
|
||||
"image": "infiniteproject/icecast@sha256:cd506cf3dfe31ce05fd37d7e672dbd1213e7255cc93d28ecf5a3b547af4e162c",
|
||||
"network": "icecast",
|
||||
"env-file": [
|
||||
"/var/lib/icecast-module/server.env"
|
||||
],
|
||||
"ports": [
|
||||
"8000"
|
||||
],
|
||||
"volumes": [
|
||||
"${dir:state}/icecast.xml:/etc/icecast.xml:ro",
|
||||
"${dir:logs}:/var/log/icecast"
|
||||
],
|
||||
"restart-on": [
|
||||
"server-conf"
|
||||
]
|
||||
"secrets-in-environment": "the image seds ICECAST_*_PASSWORD into icecast.xml and has no _FILE; convertible by mounting a generated icecast.xml, not yet done"
|
||||
},
|
||||
{
|
||||
"id": "runtime-config",
|
||||
@@ -100,14 +65,14 @@
|
||||
"id": "runtime",
|
||||
"type": "container",
|
||||
"name": "mesh-icecast",
|
||||
"network": "icecast",
|
||||
"network": "host",
|
||||
"volumes": [
|
||||
"/var/lib/mesh/icecast/broker:/run/secrets/broker:ro",
|
||||
"/var/lib/mesh/icecast/config.json:/run/config/config.json:ro"
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_ICECAST_URL": "http://icecast:8000",
|
||||
"MESH_ICECAST_URL": "http://127.0.0.1:8000",
|
||||
"MESH_ICECAST_CONFIG_FILE": "/run/config/config.json"
|
||||
},
|
||||
"restart-on": [
|
||||
@@ -136,5 +101,15 @@
|
||||
"from": "Dockerfile"
|
||||
}
|
||||
]
|
||||
},
|
||||
"requires": [
|
||||
"secret"
|
||||
],
|
||||
"secrets": {
|
||||
"secret": {
|
||||
"source": "/var/lib/icecast-module/source.secret",
|
||||
"admin": "/var/lib/icecast-module/admin.secret",
|
||||
"relay": "/var/lib/icecast-module/relay.secret"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -58,8 +58,10 @@ export class PlexClient {
|
||||
static fromEnv(env: NodeJS.ProcessEnv = process.env): PlexClient {
|
||||
const url = env.MESH_PLEX_URL ?? `http://127.0.0.1:${env.PLEX_PORT ?? "32400"}`;
|
||||
const dataDir = env.MESH_PLEX_DATA_DIR ?? "/var/lib/plex";
|
||||
// The operator-provided token is an own-secret the mesh mounts at MESH_PLEX_TOKEN_FILE (delivered
|
||||
// by `secret accept`); prefer it, fall back to a bare env var, then to discovery from the data dir.
|
||||
// The manifest sets neither MESH_PLEX_TOKEN_FILE nor MESH_PLEX_TOKEN: the server already keeps its
|
||||
// token in Preferences.xml, read here through the manifest's read-only mount of the config dir.
|
||||
// A token the mesh minted would be one plex.tv never issued, and preferring it would break every
|
||||
// call, so the module declares no token secret. The file and env overrides stay for hand runs.
|
||||
const token = readSecret(env.MESH_PLEX_TOKEN_FILE) ?? env.MESH_PLEX_TOKEN ?? PlexClient.detectToken(dataDir);
|
||||
if (!token) throw new Error("no Plex token — set MESH_PLEX_TOKEN or make the data dir readable");
|
||||
return new PlexClient(url, token);
|
||||
|
||||
+92
-19
@@ -13,8 +13,7 @@
|
||||
"*.download.completed"
|
||||
],
|
||||
"own-secrets": {
|
||||
"broker": "/var/lib/mesh/plex/broker",
|
||||
"token": "/var/lib/mesh/plex/token"
|
||||
"broker": "/var/lib/mesh/plex/broker"
|
||||
},
|
||||
"listens": [
|
||||
{
|
||||
@@ -22,7 +21,35 @@
|
||||
"port": 32400,
|
||||
"protocol": "tcp",
|
||||
"from": "mesh",
|
||||
"why": "streaming and the app; reaching it from outside is a route grant later"
|
||||
"why": "the server itself: the apps, streaming and the web player, direct and through its route"
|
||||
},
|
||||
{
|
||||
"name": "gdm-1",
|
||||
"port": 32410,
|
||||
"protocol": "udp",
|
||||
"from": "mesh",
|
||||
"why": "G'Day Mate discovery: players on the same network find the server without signing in"
|
||||
},
|
||||
{
|
||||
"name": "gdm-2",
|
||||
"port": 32412,
|
||||
"protocol": "udp",
|
||||
"from": "mesh",
|
||||
"why": "G'Day Mate discovery"
|
||||
},
|
||||
{
|
||||
"name": "gdm-3",
|
||||
"port": 32413,
|
||||
"protocol": "udp",
|
||||
"from": "mesh",
|
||||
"why": "G'Day Mate discovery"
|
||||
},
|
||||
{
|
||||
"name": "gdm-4",
|
||||
"port": 32414,
|
||||
"protocol": "udp",
|
||||
"from": "mesh",
|
||||
"why": "G'Day Mate discovery"
|
||||
}
|
||||
],
|
||||
"accesses": [
|
||||
@@ -45,6 +72,18 @@
|
||||
{
|
||||
"path": "/services/media/audiobooks",
|
||||
"mode": "read"
|
||||
},
|
||||
{
|
||||
"path": "/services/media/sport-games",
|
||||
"mode": "read"
|
||||
},
|
||||
{
|
||||
"path": "/services/media/live-shows",
|
||||
"mode": "read"
|
||||
},
|
||||
{
|
||||
"path": "/services/media/formula-1",
|
||||
"mode": "read"
|
||||
}
|
||||
],
|
||||
"resources": [
|
||||
@@ -54,39 +93,63 @@
|
||||
"path": "/var/lib/mesh/plex",
|
||||
"mode": "0700"
|
||||
},
|
||||
{
|
||||
"id": "state",
|
||||
"type": "directory",
|
||||
"mode": "0700",
|
||||
"place": "."
|
||||
},
|
||||
{
|
||||
"id": "config",
|
||||
"type": "directory",
|
||||
"path": "/services/plex/config",
|
||||
"mode": "0700",
|
||||
"mode": "0755",
|
||||
"owner": "1000:1000"
|
||||
},
|
||||
{
|
||||
"id": "data",
|
||||
"type": "directory",
|
||||
"mode": "0755",
|
||||
"owner": "1000:1000"
|
||||
},
|
||||
{
|
||||
"id": "transcode",
|
||||
"type": "directory",
|
||||
"path": "/services/plex/transcode",
|
||||
"mode": "0700",
|
||||
"mode": "0755",
|
||||
"owner": "1000:1000"
|
||||
},
|
||||
{
|
||||
"id": "server-env",
|
||||
"type": "file",
|
||||
"path": "${dir:state}/server.env",
|
||||
"mode": "0600",
|
||||
"content": "ADVERTISE_IP=https://${bound:route:name}/\n"
|
||||
},
|
||||
{
|
||||
"id": "server",
|
||||
"type": "container",
|
||||
"name": "plex",
|
||||
"image": "plexinc/pms-docker@sha256:83a425ae9e133b1cb2cc3b809556e01c61cd8ff65c582e41b4374bc2210bac9e",
|
||||
"image": "plexinc/pms-docker@sha256:e0ab27395614a8e1a4fdf84c6bc60ac664915cfdde70c52d030c7728a1c48e14",
|
||||
"network": "host",
|
||||
"env": {
|
||||
"PLEX_UID": "1000",
|
||||
"PLEX_GID": "1000",
|
||||
"TZ": "Etc/UTC"
|
||||
},
|
||||
"env-file": [
|
||||
"${dir:state}/server.env"
|
||||
],
|
||||
"volumes": [
|
||||
"/services/plex/config:/config",
|
||||
"/services/plex/transcode:/transcode",
|
||||
"/services/media/movies:/movies",
|
||||
"/services/media/series:/series",
|
||||
"/services/media/anime:/anime",
|
||||
"/services/media/music:/music",
|
||||
"/services/media/audiobooks:/audiobooks"
|
||||
"${dir:config}:/config",
|
||||
"${dir:data}:/data",
|
||||
"${dir:transcode}:/transcode",
|
||||
"/services/media/movies:/movies:ro",
|
||||
"/services/media/series:/series:ro",
|
||||
"/services/media/anime:/anime:ro",
|
||||
"/services/media/music:/music:ro",
|
||||
"/services/media/audiobooks:/audiobooks:ro",
|
||||
"/services/media/sport-games:/sport-games:ro",
|
||||
"/services/media/live-shows:/live-shows:ro",
|
||||
"/services/media/formula-1:/formula-1:ro"
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -96,18 +159,28 @@
|
||||
"network": "host",
|
||||
"volumes": [
|
||||
"/var/lib/mesh/plex/broker:/run/secrets/broker:ro",
|
||||
"/var/lib/mesh/plex/token:/run/secrets/token:ro",
|
||||
"/services/plex/config:/var/lib/plex/config:ro"
|
||||
"${dir:config}:/var/lib/plex/config:ro"
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_PLEX_URL": "http://127.0.0.1:32400",
|
||||
"MESH_PLEX_TOKEN_FILE": "/run/secrets/token",
|
||||
"MESH_PLEX_URL": "http://127.0.0.1:${port:32400}",
|
||||
"MESH_PLEX_DATA_DIR": "/var/lib/plex"
|
||||
},
|
||||
"artifact": "runtime"
|
||||
}
|
||||
],
|
||||
"requires": [
|
||||
"route"
|
||||
],
|
||||
"contributes": {
|
||||
"route": {
|
||||
"label": "plex",
|
||||
"endpoint": "stream"
|
||||
}
|
||||
},
|
||||
"binds": {
|
||||
"route": "${dir:state}/route.json"
|
||||
},
|
||||
"build": {
|
||||
"on": [
|
||||
{
|
||||
|
||||
Reference in New Issue
Block a user