jackett: its config dir is placed, and its tools find their own key #150

Merged
mesh-admin merged 2 commits from feat/jackett-for-ace into main 2026-09-30 14:40:50 +00:00
Contributor

The manifest named /services/jackett/config and /var/lib/mesh/jackett/config.json — host
paths ADR 0112 takes out of definitions. The config dir is now a pathless directory
(${dir:config}) and the runtime's config and route binding live in a placed state dir, as
searxng does.

The image is pinned to v0.24.2627-ls34, the digest ace runs today; the old pin
(v0.24.2517-ls16) was older than the running version.

The runtime reached jackett at a fixed 127.0.0.1:9117; it now uses ${port:9117}, the
machine port the mesh actually assigned.

The tools never loaded: the client needed an API key nobody set. Like sonarr/radarr read
config.xml, it now reads APIKey from Jackett's own ServerConfig.json (the config dir is
already mounted read-only), so no secret goes into an assignment. jackett_indexers called
/api/v2.0/indexers, which is the web UI's endpoint and answers an API key with a redirect;
it now reads the Torznab t=indexers feed, and treats Torznab's 200-with- as a
failure.

Verified: catalogue key tests (MESH_CATALOGUE set, not skipped); a throwaway container of
the pinned image on a fresh 0700 1000:1000 config dir serves its UI; the client discovers
the key from the generated ServerConfig.json, lists 617 indexers through the Torznab feed,
searches via /results, and a wrong key is refused; client.ts typechecks under --strict.

Migration context (ace): jackett's HAL config is 23 MB (14 of which are old log/updater files); the Torznab clients are lidarr (via https://indexers., keeps working through the route) and stale sonarr/radarr indexers at http://jackett:9117 on HAL's proxy network (their indexers no longer exist in jackett). No secret to accept: API key and admin password travel inside the held ServerConfig.json.

The manifest named /services/jackett/config and /var/lib/mesh/jackett/config.json — host paths ADR 0112 takes out of definitions. The config dir is now a pathless directory (${dir:config}) and the runtime's config and route binding live in a placed state dir, as searxng does. The image is pinned to v0.24.2627-ls34, the digest ace runs today; the old pin (v0.24.2517-ls16) was older than the running version. The runtime reached jackett at a fixed 127.0.0.1:9117; it now uses ${port:9117}, the machine port the mesh actually assigned. The tools never loaded: the client needed an API key nobody set. Like sonarr/radarr read config.xml, it now reads APIKey from Jackett's own ServerConfig.json (the config dir is already mounted read-only), so no secret goes into an assignment. jackett_indexers called /api/v2.0/indexers, which is the web UI's endpoint and answers an API key with a redirect; it now reads the Torznab t=indexers feed, and treats Torznab's 200-with-<error> as a failure. Verified: catalogue key tests (MESH_CATALOGUE set, not skipped); a throwaway container of the pinned image on a fresh 0700 1000:1000 config dir serves its UI; the client discovers the key from the generated ServerConfig.json, lists 617 indexers through the Torznab feed, searches via /results, and a wrong key is refused; client.ts typechecks under --strict. Migration context (ace): jackett's HAL config is 23 MB (14 of which are old log/updater files); the Torznab clients are lidarr (via https://indexers.<domain>, keeps working through the route) and stale sonarr/radarr indexers at http://jackett:9117 on HAL's proxy network (their indexers no longer exist in jackett). No secret to accept: API key and admin password travel inside the held ServerConfig.json.
mesh-admin added 1 commit 2026-09-29 21:41:29 +00:00
The manifest named /services/jackett/config and /var/lib/mesh/jackett/config.json — host
paths ADR 0112 takes out of definitions. The config dir is now a pathless directory
(${dir:config}) and the runtime's config and route binding live in a placed state dir, as
searxng does.

The image is pinned to v0.24.2627-ls34, the digest ace runs today; the old pin
(v0.24.2517-ls16) was older than the running version.

The runtime reached jackett at a fixed 127.0.0.1:9117; it now uses ${port:9117}, the
machine port the mesh actually assigned.

The tools never loaded: the client needed an API key nobody set. Like sonarr/radarr read
config.xml, it now reads APIKey from Jackett's own ServerConfig.json (the config dir is
already mounted read-only), so no secret goes into an assignment. jackett_indexers called
/api/v2.0/indexers, which is the web UI's endpoint and answers an API key with a redirect;
it now reads the Torznab t=indexers feed, and treats Torznab's 200-with-<error> as a
failure.

Verified: catalogue key tests (MESH_CATALOGUE set, not skipped); a throwaway container of
the pinned image on a fresh 0700 1000:1000 config dir serves its UI; the client discovers
the key from the generated ServerConfig.json, lists 617 indexers through the Torznab feed,
searches via /results, and a wrong key is refused; client.ts typechecks under --strict.
jschoubben added 1 commit 2026-09-30 11:08:06 +00:00
sonarr, radarr, lidarr and bookshelf reached jackett as http://jackett:9117 (a HAL
container name) or https://indexers.zurag.be (its public route), typed into each app by
hand. The mesh has neither: an app now requires jackett-api and its downloads step writes
the bound address into the app.

Serves scheme, port and url-base; `at` and the machine port come from the binding. Mesh
scope, like sonarr-api: an indexer proxy shares no files with its consumers.

The pair credential is jackett's one API key. The mesh cannot mint it, so the operator
accepts it per consumer pair (ADR 0092), as #156 does for sonarr-api; a consumer's step
refuses a minted value and names the accept.
Author
Contributor

New commit 9d716ed: jackett provides jackett-api.

  • provides: {"name":"jackett-api","scope":"mesh"}. Mesh scope because an indexer proxy shares no files with its consumers, the same as sonarr-api in #156.
  • serves: scheme, port (9117, which the mesh turns into the machine port) and url-base. The mesh fills at.
  • Pair credential: jackett's one API key. The mesh can't mint it, so the operator accepts it for each consumer pair: secret accept <node> <consumer> jackett-api --provider <node> --from <file holding jackett's APIKey>. Until then the consumer's step refuses the minted value, writes nothing, and names that command.
  • Consumers: sonarr #157, radarr #158, lidarr #164 and bookshelf #163 each require it. Each has a run-once downloads step that writes the bound address and key into its jackett Torznab feeds through the app's own API.
  • Verified:
    • Catalogue tests pass with MESH_CATALOGUE set to all seven downloads branches merged together.
    • A scratch resolve on a fake ace delivered each consumer at=ace.internal, jackett's machine port, and its own sealed credential.
    • A throwaway jackett at the pinned digest answered t=indexers for a good key. For a wrong key it answered 200 <error code="100">, and the step treats that as refused.
**New commit 9d716ed: jackett provides `jackett-api`.** - **provides:** `{"name":"jackett-api","scope":"mesh"}`. Mesh scope because an indexer proxy shares no files with its consumers, the same as `sonarr-api` in #156. - **serves:** `scheme`, `port` (9117, which the mesh turns into the machine port) and `url-base`. The mesh fills `at`. - **Pair credential:** jackett's one API key. The mesh can't mint it, so the operator **accepts** it for each consumer pair: `secret accept <node> <consumer> jackett-api --provider <node> --from <file holding jackett's APIKey>`. Until then the consumer's step refuses the minted value, writes nothing, and names that command. - **Consumers:** sonarr #157, radarr #158, lidarr #164 and bookshelf #163 each require it. Each has a run-once `downloads` step that writes the bound address and key into its jackett Torznab feeds through the app's own API. - **Verified:** - Catalogue tests pass with `MESH_CATALOGUE` set to all seven downloads branches merged together. - A scratch resolve on a fake ace delivered each consumer `at=ace.internal`, jackett's machine port, and its own sealed credential. - A throwaway jackett at the pinned digest answered `t=indexers` for a good key. For a wrong key it answered `200 <error code="100">`, and the step treats that as refused.
mesh-admin merged commit 36b35900a2 into main 2026-09-30 14:40:50 +00:00
mesh-admin deleted branch feat/jackett-for-ace 2026-09-30 14:40:50 +00:00
Sign in to join this conversation.
No Reviewers
No labels
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#150