Compare commits

..
Author SHA1 Message Date
jschoubben 287e5e6d3f bookshelf: its config dir is placed, its image is the one ace runs
The config directory was the stated path /services/bookshelf/config; it
is now a pathless directory the mesh places (0700, 1000:1000), and the
route binding lives in a placed state dir, as in jackett and searxng.
/var/lib/mesh/bookshelf stays for the broker secret.

The image is pinned to the digest ace runs (hardcover, 0.4.21.182,
ls36). The old pin was a February build: older than the database it
would open, which Readarr-family apps migrate forward only.

The sidecar dials ${port:8787}, the port the mesh assigned, not the
software's own (the same one-line change as #154).

Not carried from HAL: its install hook seeded config.xml with an API key
(the image writes its own on first start, and the data keeps it) and
registered nzbget, qbittorrent and jackett through the API with wrong
hosts and ports, so ace's bookshelf has no download client and no
indexer today. Wiring them is provisioning work that depends on the
download-client and jackett providers, and on where ace's books and
downloads live (hq 153).

Verified: catalogue tests with MESH_CATALOGUE; a scratch resolution with
ace's assignment composes books.zurag.be and keeps the port to the
mesh; a throwaway container at the pinned digest on a fresh 0700
1000:1000 dir answered /ping and /api/v1/system/status (401 on a wrong
key); client.ts typechecks strict, found the key in config.xml and read
the queue.
2026-09-30 11:58:37 +02:00
2 changed files with 27 additions and 20 deletions
+11 -6
View File
@@ -39,10 +39,15 @@
"path": "/var/lib/mesh/bookshelf",
"mode": "0700"
},
{
"id": "state",
"type": "directory",
"mode": "0700",
"place": "."
},
{
"id": "config",
"type": "directory",
"path": "/services/bookshelf/config",
"mode": "0700",
"owner": "1000:1000"
},
@@ -50,7 +55,7 @@
"id": "server",
"type": "container",
"name": "bookshelf",
"image": "ghcr.io/pennydreadful/bookshelf@sha256:388eecc94362580eae31ee0a454be6af516f8a311f8432a521c202fb475f4359",
"image": "ghcr.io/pennydreadful/bookshelf@sha256:67498dd5ece516867d72ee642abd6c1a66b36a135c8f7da0127109564372beb1",
"env": {
"PUID": "1000",
"PGID": "1000",
@@ -60,7 +65,7 @@
"8787"
],
"volumes": [
"/services/bookshelf/config:/config",
"${dir:config}:/config",
"/services/media/books:/books",
"/services/media/downloads:/downloads"
]
@@ -72,11 +77,11 @@
"network": "host",
"volumes": [
"/var/lib/mesh/bookshelf/broker:/run/secrets/broker:ro",
"/services/bookshelf/config:/var/lib/bookshelf/config:ro"
"${dir:config}:/var/lib/bookshelf/config:ro"
],
"env": {
"MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_BOOKSHELF_URL": "http://127.0.0.1:8787",
"MESH_BOOKSHELF_URL": "http://127.0.0.1:${port:8787}",
"MESH_BOOKSHELF_CONFIG_DIR": "/var/lib/bookshelf/config"
},
"artifact": "runtime"
@@ -92,7 +97,7 @@
}
},
"binds": {
"route": "/var/lib/mesh/bookshelf/route.json"
"route": "${dir:state}/route.json"
},
"build": {
"on": [
+16 -14
View File
@@ -23,13 +23,13 @@
"mqtt-topic": {}
},
"receives": {
"mqtt-topic": "${dir:grants}/mesh.json"
"mqtt-topic": "/var/lib/mosquitto-module/grants/mesh.json"
},
"grants": {
"mqtt-topic": "${dir:grants}"
"mqtt-topic": "/var/lib/mosquitto-module/grants"
},
"own-secrets": {
"admin": "/var/lib/mesh/mosquitto/admin",
"admin": "/var/lib/mosquitto-module/admin.secret",
"broker": "/var/lib/mesh/mosquitto/broker"
},
"listens": [
@@ -58,24 +58,26 @@
{
"id": "state",
"type": "directory",
"mode": "0700",
"place": "."
"path": "/var/lib/mosquitto-module",
"mode": "0700"
},
{
"id": "grants",
"id": "grants-dir",
"type": "directory",
"path": "/var/lib/mosquitto-module/grants",
"mode": "0700"
},
{
"id": "data",
"type": "directory",
"path": "/services/mosquitto/data",
"mode": "0700",
"owner": "1883:1883"
},
{
"id": "server-conf",
"type": "file",
"path": "${dir:state}/mosquitto.conf",
"path": "/var/lib/mosquitto-module/mosquitto.conf",
"mode": "0600",
"owner": "1883:1883",
"content": "persistence true\npersistence_location /mosquitto/data\n\nlog_dest stdout\nlog_type warning\nlog_type error\nlog_type notice\n\n# Every client authenticates; identities and their per-topic ACLs are managed\n# at runtime by the dynamic security plugin, whose store the plugin itself owns.\nallow_anonymous false\nplugin /usr/lib/mosquitto_dynamic_security.so\nplugin_opt_config_file /mosquitto/data/dynamic-security.json\n\n# MQTT listener\nlistener 1883\n\n# MQTT-over-WebSockets listener\nlistener 8081\nprotocol websockets\n"
@@ -91,8 +93,8 @@
"name": "mosquitto-bootstrap",
"run-once": true,
"volumes": [
"${dir:data}:/mosquitto/data",
"/var/lib/mesh/mosquitto/admin:/run/secrets/admin:ro"
"/services/mosquitto/data:/mosquitto/data",
"/var/lib/mosquitto-module/admin.secret:/run/secrets/admin:ro"
],
"env": {
"MESH_PROVISION_MQTT": "mosquitto:1883",
@@ -110,15 +112,15 @@
"id": "server",
"type": "container",
"name": "mosquitto",
"image": "eclipse-mosquitto@sha256:38c0da4f2ef84284d47b3b3eeea1cb3bdeabe81ee10caf0cd5c5ff61ee3ea408",
"image": "eclipse-mosquitto@sha256:6f8d8a947c506f8a2290ec65cd4bd2bc7cb4d43fb5f6271f861cb013e2ef9797",
"network": "mosquitto",
"ports": [
"1883",
"8081"
],
"volumes": [
"${dir:data}:/mosquitto/data",
"${dir:state}/mosquitto.conf:/mosquitto/config/mosquitto.conf:ro"
"/services/mosquitto/data:/mosquitto/data",
"/var/lib/mosquitto-module/mosquitto.conf:/mosquitto/config/mosquitto.conf:ro"
]
},
{
@@ -128,8 +130,8 @@
"network": "mosquitto",
"volumes": [
"/var/lib/mesh/mosquitto/broker:/run/secrets/broker:ro",
"${dir:grants}:/var/lib/mosquitto-module/grants:ro",
"/var/lib/mesh/mosquitto/admin:/run/secrets/admin:ro"
"/var/lib/mosquitto-module/grants:/var/lib/mosquitto-module/grants:ro",
"/var/lib/mosquitto-module/admin.secret:/run/secrets/admin:ro"
],
"env": {
"MESH_BROKER_FILE": "/run/secrets/broker",