Implements ADR 0051 in the catalogue. All eight media modules (plex, sonarr, radarr, nzbget, qbittorrent, bazarr, lidarr, bookshelf): every /services/media/* path moves from an owned directory resource to an accesses entry (operator-owned); each module's own config and /var/lib/mesh/* dirs stay owned; container volume mounts unchanged. Modes are least-privilege (plex read-only on libraries as a player; managers/clients read-write on what they import).
Implements ADR 0051 in the catalogue. All eight media modules (plex, sonarr, radarr, nzbget, qbittorrent, bazarr, lidarr, bookshelf): every `/services/media/*` path moves from an owned `directory` resource to an `accesses` entry (operator-owned); each module's own `config` and `/var/lib/mesh/*` dirs stay owned; container volume mounts unchanged. Modes are least-privilege (plex read-only on libraries as a player; managers/clients read-write on what they import).
https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
04-ISSUES/036: eight media modules each declared the shared library and
download directories under /services/media/* as their own `directory`
resources. Six of them owning one path is the collision the resolver
refuses — so the stack's only sensible assignment, all on one machine
sharing one filesystem, would be refused the first time two landed
together.
The media library is the operator's, owned by no module (novox/hq
ADR 0051). Move every /services/media/* path from an owned `directory`
resource to an `accesses` entry: the mesh mounts it and owns nothing —
does not create, chown, reconcile or remove it — and several modules may
access one path with no conflict. Each module's own config and mesh-state
directories stay owned resources.
Modes are least-privilege: plex reads the libraries it streams; the
managers and download clients get read-write on what they import and
write; bazarr writes subtitles into the libraries (read-write) and only
reads the download spool. The container volume mounts are unchanged.
Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Implements ADR 0051 in the catalogue. All eight media modules (plex, sonarr, radarr, nzbget, qbittorrent, bazarr, lidarr, bookshelf): every
/services/media/*path moves from an owneddirectoryresource to anaccessesentry (operator-owned); each module's ownconfigand/var/lib/mesh/*dirs stay owned; container volume mounts unchanged. Modes are least-privilege (plex read-only on libraries as a player; managers/clients read-write on what they import).https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF