kometa: a nightly scheduled run against plex, its credentials as files #159
Closed
mesh-admin
wants to merge 2 commits from
feat/kometa-for-ace into main
pull from: feat/kometa-for-ace
merge into: :main
:main
:fix/resolver-passes-the-dnssec-bit
:fix/mailu-admin-asks-the-machines-resolver
:fix/110-the-resolver-answers-a-container
:feat/qbittorrent-for-ace
:feat/servarr-api-provision
:feat/home-assistant-for-ace
:feat/tautulli-for-ace
:feat/bookshelf-for-ace
:feat/lidarr-for-ace
:feat/radarr-for-ace
:feat/sonarr-for-ace
:feat/kometa-for-ace
:feat/plex-for-ace
:fix/manifests-publish-software-ports
:feat/nzbget-for-ace
:feat/bazarr-for-ace
:fix/sidecars-dial-the-port-they-were-given
:feat/ombi-for-ace
:chore/remove-the-network-checker-module
:feat/a-network-checker-module
:feat/modules-name-their-endpoints
:fix/a-routed-module-listens-from-the-mesh
:fix/the-resolver-declares-both-protocols
:fix/sshd-declares-the-daemon-it-owns
:fix/fail2ban-bans-through-what-every-machine-has
:fix/fail2ban-declares-the-log-its-own-jail-reads
:fix/fail2ban-restarts-on-its-log-target
:fix/fail2ban-declares-where-it-logs
:feat/the-catalogue-hears-what-it-missed
:feat/the-catalogue-prepares-its-own-schema
:fix/the-catalogue-declares-the-event-it-emits
:feat/a-merge-rebuilds-what-it-changed
:fix/a-merge-older-than-the-watching-is-history
:fix/a-merge-announced-is-said
:fix/the-forge-watches-every-repository
:feat/the-forge-announces-every-merge
:feat/nats-serves-the-meshs-certificate
:fix/nats-declares-its-base
:feat/amqp-leaves-the-catalogue
:restore/broker-claim
:revert/broker-seat-claim
:fix/broker-seat-must-stay-held
:fix/go-126-base
:feat/nats-genesis
:feat/ssh-client-module
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
New module: kometa (ace runs it under HAL today).
"schedule": "0 3 * * *",kometa --run(ADR 0053) — replaces HAL's always-on container with Kometa's own 03:00 scheduler.config.yml(0600, root, read-only,KOMETA_READ_ONLY_CONFIG=true) carries${secret:plex-api}and${secret:tmdb}; HAL passed both through the environment.requires: ["plex-api", "secret"],${bound:plex-api:at|port}; the Plex token is the accepted pair credential (ADR 0092), the TMDb key an accepted vault secret.provide/serveplex-api({"scheme":"http","port":32400}, scope mesh). Plex was outside this change's scope; kometa is unassignable until that lands."libraries": {}by default; the assignment merges them in (ace: Formula 1, metadata from f1-circuits' public name).Verified: catalogue tests (MESH_CATALOGUE set) on mesh-controller main and #149; a stub-provider resolution renders binding, secrets and the merged config; the pinned image with the rendered file root-owned 0600 :ro parses it, tolerates
endpoints, never writes back, and stops only at TMDb refusing the dummy key.ace runs Kometa under HAL as a long-lived container whose own scheduler wakes at 03:00, with the Plex token and the TMDb key in its environment (KOMETA_PLEX_TOKEN, KOMETA_TMDB_APIKEY). This is the case ADR 0053 was written for: the module is one container marked "schedule": "0 3 * * *" that runs kometa --run to completion, so nothing stays up between runs. Secrets are files (ADR 0086): config.yml is rendered by the mesh, 0600 and root-owned (Kometa runs as root), with ${secret:plex-api} and ${secret:tmdb} in it, and mounted read-only. KOMETA_READ_ONLY_CONFIG stops Kometa writing its defaults back into it (without it the run dies on EROFS); the file already carries every attribute Kometa filled in on ace, so behaviour is unchanged. Plex is reached through provisioning, not a URL: kometa requires plex-api and reads ${bound:plex-api:at|port}; the token is that pair's credential, which the operator accepts (ADR 0092). The provider half (plex provides and serves plex-api, 32400) is NOT in this change: plex is outside this work, so until plex declares it kometa cannot be assigned. The TMDb key is an operator-accepted vault secret. Which libraries Kometa manages is per machine: the manifest ships "libraries": {}, and config.yml is the module's one merge:json file, so the assignment supplies them (ace: the Formula 1 library, whose metadata file comes from f1-circuits' public name). Verified: catalogue tests with MESH_CATALOGUE pointed here, on mesh-controller main and on #149; a resolution with stub providers renders the binding, the two secret files and config.yml with the assignment's library merged in; the pinned digest (the one ace runs, 2.4.8) in a throwaway container with the rendered file root-owned 0600 read-only: config parses, the "endpoints" key is tolerated, no write-back with the read-only flag, and the run stops only at TMDb refusing the dummy key.kometa: the whole Plex URL now comes from the binding (commit
2ee77de)httpwhile the host and port came fromplex-api. plex now serves its scheme (#162), so the URL is${bound:plex-api:scheme}://${bound:plex-api:at}:${bound:plex-api:port}. On ace it rendershttp://ace.internal:32400(checked with a scratch Resolve/Declaration).${secret:plex-api}fills from kometa's own pair credential.secret accept ace kometa plex-api --provider ace --from <file>.--run. Kometa checks the TMDb key first, and that key is an operator secret.Superseded: this module now lives in novox/mesh-media-catalog (the media chain, consolidated from #145–#168 in stack order; its non-media parts merged via #195). Closing.
Pull request closed