plex: placed state, the build ace runs, its own name from the route, all eight libraries read-only #162
Open
mesh-admin
wants to merge 2 commits from
feat/plex-for-ace into main
pull from: feat/plex-for-ace
merge into: :main
:main
:fix/110-the-resolver-answers-a-container
:feat/qbittorrent-for-ace
:feat/servarr-api-provision
:feat/home-assistant-for-ace
:feat/tautulli-for-ace
:feat/bookshelf-for-ace
:feat/lidarr-for-ace
:feat/radarr-for-ace
:feat/sonarr-for-ace
:feat/jackett-for-ace
:feat/oidc-client-provision
:feat/mosquitto-placed
:feat/nodered-for-ace
:feat/influxdb-for-ace
:feat/kometa-for-ace
:feat/plex-for-ace
:fix/manifests-publish-software-ports
:feat/n8n-for-ace
:feat/letta-for-ace
:feat/baserow-for-ace
:feat/supabase-for-ace
:feat/nzbget-for-ace
:feat/matrix-for-ace
:feat/bazarr-for-ace
:feat/redis-for-ace
:feat/mssql-for-ace
:fix/sidecars-dial-the-port-they-were-given
:feat/grafana-for-ace
:feat/unifi-for-ace
:feat/icecast-for-ace
:feat/ombi-for-ace
:chore/remove-the-network-checker-module
:feat/a-network-checker-module
:feat/modules-name-their-endpoints
:fix/a-routed-module-listens-from-the-mesh
:fix/the-resolver-declares-both-protocols
:fix/sshd-declares-the-daemon-it-owns
:fix/fail2ban-bans-through-what-every-machine-has
:fix/fail2ban-declares-the-log-its-own-jail-reads
:fix/fail2ban-restarts-on-its-log-target
:fix/fail2ban-declares-where-it-logs
:feat/the-catalogue-hears-what-it-missed
:feat/the-catalogue-prepares-its-own-schema
:fix/the-catalogue-declares-the-event-it-emits
:feat/a-merge-rebuilds-what-it-changed
:fix/a-merge-older-than-the-watching-is-history
:fix/a-merge-announced-is-said
:fix/the-forge-watches-every-repository
:feat/the-forge-announces-every-merge
:feat/nats-serves-the-meshs-certificate
:fix/nats-declares-its-base
:feat/amqp-leaves-the-catalogue
:restore/broker-claim
:revert/broker-seat-claim
:fix/broker-seat-must-stay-held
:fix/go-126-base
:feat/nats-genesis
:feat/ssh-client-module
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The manifest named /services/plex/{config,transcode} with owner and mode.
On ace /services/plex is a link to /mnt/plex, plex's 133 GB of state, so
a take would have chmod'ed 0700 the top of the one directory the operator
ruled must never be re-moded or re-owned. The directories are now pathless
(config, data, transcode), placed by the mesh; on an adopted machine they
must be placed where the data is (hq 153) before plex is ever taken.
/data (HAL mounts it; the catalogue did not), /transcode and all eight
libraries, including sport-games, live-shows and formula-1. A library
whose mount disappears is emptied by Plex's automatic trash emptying,
taking its watch state with it.
PLEX_UID, not the PUID HAL passes), pms-docker leaves its dirs 0755, and
ace's /mnt/plex is 1000:1000 0755 - so placing adopted data is a no-op.
(${bound:route:name}); it depends on mesh-controller #149, and without
it the declaration is refused, not applied.
ports, which LAN players use.
preferred it. The sidecar reads PlexOnlineToken from Preferences.xml
through its read-only config mount, and dials ${port:32400}.
Verified: catalogue tests with MESH_CATALOGUE (parse, mounts); a scratch
resolution with ace's assignment on the #149 controller renders
ADVERTISE_IP=https://plex.zurag.be/, both route names and 32400/tcp +
GDM/udp open to anywhere; on main it is refused naming "name". A
throwaway pms-docker at the pinned digest on empty dirs answered
/identity, wrote customConnections from the env-file and ran as 1000;
client.ts typechecks strict and found the token in a Preferences.xml.
Depends on mesh-controller #149 (
${bound:route:name}). Without it the declaration is refused, not applied.Do not assign on ace before hq 153 lands. The config, data and transcode directories must be placed at /mnt/plex/{config,data,temp} (133 GB, held in place, never copied), and the accesses at /storage/media/*. The assignment draft is ace-assignments/plex.json in the migration repo: endpoints stream (32400, label plex) and gdm-1..4 (public), plus expose 32400 anywhere. The routed port uses
exposebecause a routed endpoint's reach sets names only, and LAN players and the router's forward dial 32400 directly.The manifest named /services/plex/{config,transcode} with owner and mode. On ace /services/plex is a link to /mnt/plex, plex's 133 GB of state, so a take would have chmod'ed 0700 the top of the one directory the operator ruled must never be re-moded or re-owned. The directories are now pathless (config, data, transcode), placed by the mesh; on an adopted machine they must be placed where the data is (hq 153) before plex is ever taken. - The container sees exactly the paths ace's plex sees today: /config, /data (HAL mounts it; the catalogue did not), /transcode and all eight libraries, including sport-games, live-shows and formula-1. A library whose mount disappears is emptied by Plex's automatic trash emptying, taking its watch state with it. - Libraries are mounted read-only, as the accesses already said. - Owner 1000:1000 and mode 0755: plex runs as uid 1000 (the image reads PLEX_UID, not the PUID HAL passes), pms-docker leaves its dirs 0755, and ace's /mnt/plex is 1000:1000 0755 - so placing adopted data is a no-op. - Image pinned to what ace runs, 1.43.4.10903; the old pin was 1.43.3. - ADVERTISE_IP comes from the route's own public name through an env-file (${bound:route:name}); it depends on mesh-controller #149, and without it the declaration is refused, not applied. - The server is routed (label plex) and declares its four GDM discovery ports, which LAN players use. - No token secret: a minted one is not a Plex token and the sidecar preferred it. The sidecar reads PlexOnlineToken from Preferences.xml through its read-only config mount, and dials ${port:32400}. Verified: catalogue tests with MESH_CATALOGUE (parse, mounts); a scratch resolution with ace's assignment on the #149 controller renders ADVERTISE_IP=https://plex.zurag.be/, both route names and 32400/tcp + GDM/udp open to anywhere; on main it is refused naming "name". A throwaway pms-docker at the pinned digest on empty dirs answered /identity, wrote customConnections from the env-file and ran as 1000; client.ts typechecks strict and found the token in a Preferences.xml.plex now provides
plex-api(commit4213fa7)provides: [{name: plex-api, scope: mesh}],serves: {plex-api: {scheme: http, port: 32400}}. The port is written out: plex listens on five ports, and the mesh only infers a provision's port when a module listens on exactly one.go test ./internal/catalogue/passes with all four branches merged, on controller main and on #149. 74 manifests parse.at=ace.internal,port=32400andscheme=http, and its own sealed pair credential.endpointsandexpose) are merged into what it serves, so every consumer's plex-api binding also carries them. This is harmless for these consumers, which read onlyportandscheme, but it is noise, and a setting namedportwould redirect consumers. A proposed hq issue is in the report.View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.