sonarr: its config dir is placed, its image is the one ace runs #157
Closed
mesh-admin
wants to merge 7 commits from
feat/sonarr-for-ace into main
pull from: feat/sonarr-for-ace
merge into: :main
:main
:fix/resolver-passes-the-dnssec-bit
:fix/mailu-admin-asks-the-machines-resolver
:fix/110-the-resolver-answers-a-container
:feat/qbittorrent-for-ace
:feat/servarr-api-provision
:feat/home-assistant-for-ace
:feat/tautulli-for-ace
:feat/bookshelf-for-ace
:feat/lidarr-for-ace
:feat/radarr-for-ace
:feat/sonarr-for-ace
:feat/kometa-for-ace
:feat/plex-for-ace
:fix/manifests-publish-software-ports
:feat/nzbget-for-ace
:feat/bazarr-for-ace
:fix/sidecars-dial-the-port-they-were-given
:feat/ombi-for-ace
:chore/remove-the-network-checker-module
:feat/a-network-checker-module
:feat/modules-name-their-endpoints
:fix/a-routed-module-listens-from-the-mesh
:fix/the-resolver-declares-both-protocols
:fix/sshd-declares-the-daemon-it-owns
:fix/fail2ban-bans-through-what-every-machine-has
:fix/fail2ban-declares-the-log-its-own-jail-reads
:fix/fail2ban-restarts-on-its-log-target
:fix/fail2ban-declares-where-it-logs
:feat/the-catalogue-hears-what-it-missed
:feat/the-catalogue-prepares-its-own-schema
:fix/the-catalogue-declares-the-event-it-emits
:feat/a-merge-rebuilds-what-it-changed
:fix/a-merge-older-than-the-watching-is-history
:fix/a-merge-announced-is-said
:fix/the-forge-watches-every-repository
:feat/the-forge-announces-every-merge
:feat/nats-serves-the-meshs-certificate
:fix/nats-declares-its-base
:feat/amqp-leaves-the-catalogue
:restore/broker-claim
:revert/broker-seat-claim
:fix/broker-seat-must-stay-held
:fix/go-126-base
:feat/nats-genesis
:feat/ssh-client-module
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Converts sonarr for ace's HAL → nox-mesh cutover. Conversion only — nothing is assigned.
Depends on #156 (feat/servarr-api-provision is merged into this branch: sonarr provides
sonarr-api). Merge #156 first; until then this diff also shows #156's commits.Changes
configis a pathless${dir:config}(0700, 1000:1000); the route binding moves to a placedstatedir (${dir:state}/route.json)./var/lib/mesh/sonarrstays for the broker secret. No host path of the module's own remains (ADR 0112)./series, /anime, /downloads: the database stores root folders and download paths under those names and has no remote path mappings./storage/...paths and the media owner 1001:2000 wait on hq 153.Verified
MESH_CATALOGUE=<worktree> go test -count=1 ./internal/catalogue/— 73 manifests parsed (not skipped)./pingOK, v3 API answers with its generated key, a wrong key gets 401, the root folder is writable; the runtime's client (client.ts) discovers the key from thatconfig.xmland reads the queue. Removed afterwards.Not in this PR (needs a decision, reported to the operator)
Sonarr reaches its download clients (NZBGet, qBittorrent) and Jackett's Torznab feeds by container name on HAL's network (
nzbget:6789,qbittorrent:8112,jackett:9117). Expressing that as provisioning needs providers in nzbget, qbittorrent and jackett (outside this change) and a consumer step writing host/port/key into Sonarr's own database through its API, like ombi's in #156. Until then those connections are repointed by hand in the migration window.ombi's definition named /services/ombi/config (a HAL machine path) in three places and pinned an image older than the one ace runs. Ombi migrates its own SQLite schema, so a take onto the older pin (v4.53.10-ls267) would start it on a database the newer build (ls269) already touched. - config is a pathless placed directory, mounted as ${dir:config} - a state directory placed at the assignment root carries route.json - image pinned to the digest ace runs today (v4.53.10-ls269) - the sidecar reaches ombi on the machine port the mesh assigns (${port:3579}) rather than assuming 3579 is free - the sidecar no longer mounts ombi's data directory: MESH_OMBI_CONFIG_DIR is read by no code, and the mount exposed the databases for nothing Verified: catalogue tests (MESH_CATALOGUE set, 6 pass, none skipped); the pinned image starts as PUID 1000 in a 0700 dir and answers /api/v1/Status 200; data owned 1001:2000 (ace's media ids) under a 1000:1000 dir is re-owned by the image's init and serves 200; a minted ApiKey is refused (401) - the api-key secret must be accepted from ombi's own settings.A host-network sidecar reaches its service over the machine's loopback, and the mesh publishes that service on a machine port it assigns (ADR 0038) — so dialling the software's port reaches whatever else holds it. On ace, searxng's sidecar dialled 127.0.0.1:8080 and got unifi's inform port. The same shape in bazarr, bookshelf, lidarr, nzbget, qbittorrent, radarr and sonarr; each now asks with ${port:N} (hq 088). Found in review of ace's module preparation.The manifest named /services/sonarr/config and /var/lib/mesh/sonarr/route.json, host paths ADR 0112 takes out of definitions. The config dir is now a pathless ${dir:config} (0700, 1000:1000) mounted into the server and, read-only, into the runtime that reads the API key from config.xml; the route binding lives in a placed state dir, as jackett and searxng do. /var/lib/mesh/sonarr stays for the broker secret. The image is pinned to 4.0.20.3014-ls325, the digest ace runs today. The old pin (4.0.19.2979-ls322) was older than the running version, and Sonarr migrates its database forward on start, so pointing the older build at ace's data is not safe. The container mount points stay /series, /anime and /downloads: Sonarr's database stores its root folders and the download clients' reported paths under exactly those names, and there are no remote path mappings to absorb a change. The generic access paths stay; ace's (/storage/media/*, /storage/downloads) and its media owner 1001:2000 wait on hq 153. Based on feat/servarr-api-provision (#156), which makes sonarr provide sonarr-api. Verified: catalogue key tests with MESH_CATALOGUE set (73 manifests parsed, not skipped); a throwaway container of the pinned image on a fresh 0700 1000:1000 config dir answers /ping, serves the v3 API with the key it generated and refuses a wrong one (401), accepts /series as a writable root folder; the runtime's client discovers the key from that config.xml and reads the queue.New commit
28b756f: sonarr reaches nzbget, qbittorrent and jackett through the mesh.Manifest
nzbget-api(#167),qbittorrent-api(#168) andjackett-api(#150).${dir:state}.downloads-config:${dir:state}/downloads.json, merge json, carryingnode: ${machine:name}and thedownloads.*settings.downloads-memory: a directory.downloads: a run-once step on the host network, declared last. It restarts when the settings, any of the three bindings or any of the three secrets change.What the step does, through sonarr's own API:
downloads.<provision>.nameand whose kind matches that provider. If there is none, the step registers one.at, a host the step pointed feeds at before (kept indownloads-memory), or a host listed indownloads.jackett-api.adopt-hosts. A jackett indexer listed indownloads.jackett-api.indexersthat the app lacks is registered.secret accept <node> sonarr <provision> --provider <node> --from <file>.test/downloads.test.tsfails if a sibling's copy differs.On ace (the draft
ace-assignments/sonarr.jsonadds this):downloads: {nzbget-api: {name: "NZBGet"}, qbittorrent-api: {name: "qBitTorrent"}, jackett-api: {adopt-hosts: ["jackett"]}}. That adopts the two clients and the disabled "Jackett - RARBG" feed the migration plan names. RARBG's jackett indexer no longer exists, so that feed is repointed and reported as untested. Accept the three pair credentials (nzbget ControlPassword, qBittorrent WebUI password, jackett APIKey) before the first apply.Verified
MESH_CATALOGUEset to all seven downloads branches merged. A scratch resolve on a fake ace filled every${bound},${port},${machine},${dir}and each consumer's own sealed credential, and the step is the module's last container.NZBGetatnzbget:6789,qBitTorrentwith an old password, disabled feeds atjackett:9117including one dead one) was repointed.Superseded: this module now lives in novox/mesh-media-catalog (the media chain, consolidated from #145–#168 in stack order; its non-media parts merged via #195). Closing.
Pull request closed