plex: placed state, the build ace runs, its own name from the route, all eight libraries read-only #162

Closed
mesh-admin wants to merge 2 commits from feat/plex-for-ace into main
2 Commits
Author SHA1 Message Date
jschoubben 4213fa7a2d plex: provide its API to the mesh as plex-api
kometa, tautulli and ombi reached plex by a hand-typed address - a public
name, a HAL network gateway - which the mesh cannot keep true. Plex now
provides plex-api at mesh scope and serves the server's port and scheme, so
the mesh tells each consumer where it is.

The port is written out rather than inferred: plex listens on five ports
(the server and four discovery ones), and the mesh only infers a provision's
port when a module listens on exactly one.

No grants and no provisioner: the credential is the server owner's
X-Plex-Token, which plex.tv issues and the mesh cannot mint. The operator
accepts it as the pair credential for each consumer (ADR 0092); each
consumer's step checks it against the server and writes nothing it refuses.
2026-09-30 12:55:24 +02:00
jschoubben 8dcdd45660 plex: its state is placed, not written over ace's disk
The manifest named /services/plex/{config,transcode} with owner and mode.
On ace /services/plex is a link to /mnt/plex, plex's 133 GB of state, so
a take would have chmod'ed 0700 the top of the one directory the operator
ruled must never be re-moded or re-owned. The directories are now pathless
(config, data, transcode), placed by the mesh; on an adopted machine they
must be placed where the data is (hq 153) before plex is ever taken.

- The container sees exactly the paths ace's plex sees today: /config,
  /data (HAL mounts it; the catalogue did not), /transcode and all eight
  libraries, including sport-games, live-shows and formula-1. A library
  whose mount disappears is emptied by Plex's automatic trash emptying,
  taking its watch state with it.
- Libraries are mounted read-only, as the accesses already said.
- Owner 1000:1000 and mode 0755: plex runs as uid 1000 (the image reads
  PLEX_UID, not the PUID HAL passes), pms-docker leaves its dirs 0755, and
  ace's /mnt/plex is 1000:1000 0755 - so placing adopted data is a no-op.
- Image pinned to what ace runs, 1.43.4.10903; the old pin was 1.43.3.
- ADVERTISE_IP comes from the route's own public name through an env-file
  (${bound:route:name}); it depends on mesh-controller #149, and without
  it the declaration is refused, not applied.
- The server is routed (label plex) and declares its four GDM discovery
  ports, which LAN players use.
- No token secret: a minted one is not a Plex token and the sidecar
  preferred it. The sidecar reads PlexOnlineToken from Preferences.xml
  through its read-only config mount, and dials ${port:32400}.

Verified: catalogue tests with MESH_CATALOGUE (parse, mounts); a scratch
resolution with ace's assignment on the #149 controller renders
ADVERTISE_IP=https://plex.zurag.be/, both route names and 32400/tcp +
GDM/udp open to anywhere; on main it is refused naming "name". A
throwaway pms-docker at the pinned digest on empty dirs answered
/identity, wrote customConnections from the env-file and ran as 1000;
client.ts typechecks strict and found the token in a Preferences.xml.
2026-09-30 11:57:15 +02:00