bazarr: reach sonarr and radarr through the mesh; placed dirs; the image ace runs #165
Closed
mesh-admin
wants to merge 6 commits from
feat/bazarr-for-ace into main
pull from: feat/bazarr-for-ace
merge into: :main
:main
:fix/resolver-passes-the-dnssec-bit
:fix/mailu-admin-asks-the-machines-resolver
:fix/110-the-resolver-answers-a-container
:feat/qbittorrent-for-ace
:feat/servarr-api-provision
:feat/home-assistant-for-ace
:feat/tautulli-for-ace
:feat/bookshelf-for-ace
:feat/lidarr-for-ace
:feat/radarr-for-ace
:feat/sonarr-for-ace
:feat/kometa-for-ace
:feat/plex-for-ace
:fix/manifests-publish-software-ports
:feat/nzbget-for-ace
:feat/bazarr-for-ace
:fix/sidecars-dial-the-port-they-were-given
:feat/ombi-for-ace
:chore/remove-the-network-checker-module
:feat/a-network-checker-module
:feat/modules-name-their-endpoints
:fix/a-routed-module-listens-from-the-mesh
:fix/the-resolver-declares-both-protocols
:fix/sshd-declares-the-daemon-it-owns
:fix/fail2ban-bans-through-what-every-machine-has
:fix/fail2ban-declares-the-log-its-own-jail-reads
:fix/fail2ban-restarts-on-its-log-target
:fix/fail2ban-declares-where-it-logs
:feat/the-catalogue-hears-what-it-missed
:feat/the-catalogue-prepares-its-own-schema
:fix/the-catalogue-declares-the-event-it-emits
:feat/a-merge-rebuilds-what-it-changed
:fix/a-merge-older-than-the-watching-is-history
:fix/a-merge-announced-is-said
:fix/the-forge-watches-every-repository
:feat/the-forge-announces-every-merge
:feat/nats-serves-the-meshs-certificate
:fix/nats-declares-its-base
:feat/amqp-leaves-the-catalogue
:restore/broker-claim
:revert/broker-seat-claim
:fix/broker-seat-must-stay-held
:fix/go-126-base
:feat/nats-genesis
:feat/ssh-client-module
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Prepares bazarr for ace. Conversion only — nothing assigned, deployed or moved.
Depends on #156 (feat/servarr-api-provision), which this branch contains: bazarr consumes the
sonarr-api/radarr-apiprovisions it adds. Merge #156 first. Does not need controller #149.What changed
sonarr:8989/radarr:7878— container names on HAL's network, which the mesh does not have. It nowrequiressonarr-apiandradarr-api, binds them and takes their pair credentials into a placedstatedir, and a run-once step (servarr/, same shape as ombi's in #156) writes host, port, TLS, base path and key into bazarr through bazarr's ownPOST /api/system/settings— only the fields that differ, then reads them back.use_sonarr, sync intervals, excluded tags, path mappings: untouched. The mesh does not write bazarr'sconfig.yaml(bazarr holds it in memory and rewrites it). A key the app refuses — a minted credential before the operator accepts the app's own — is never written; the step fails naming thesecret accept. Declared last (ADR 0136),restart-onits four inputs (ADR 0099).api-keyown-secret is removed. bazarr makes its own key and nothing lets the mesh set it, so a minted value could never work. Tools and the step readauth.apikeyfrom bazarr's ownconfig/config.yaml(config dir mounted read-only) — nothing to accept, and it follows a regenerated key.configis a pathless${dir:config};config.json, route and bindings live in${dir:state};/var/lib/mesh/bazarrkeeps only the broker.v1.6.1-ls364sha256:d24bd004…. The old pin3a820372…isv1.6.0-ls361, older than ace's database.Verified
MESH_CATALOGUE=<this> go test ./internal/catalogue/passes (not skipped).${}filled, restart-on ids exist; bazarr alone is refused naming sonarr and radarr.tsc -p tsconfig.jsonpasses; the Dockerfile's non-strict compile builds;npm test8/8.ip, port, apikey; refused radarr's minted key and wrote nothing for it; wrote radarr once the key was right; changed nothing on a third run; values persisted inconfig.yaml.Gaps
/storage/media/{movies,series,anime}+/storage/downloads; bazarr must run as1001:2000to write subtitles next to media. Not expressible yet.Etc/UTC(ace: Europe/Brussels): bazarr's backup/full-update hours shift by 1–2 h.ombi's definition named /services/ombi/config (a HAL machine path) in three places and pinned an image older than the one ace runs. Ombi migrates its own SQLite schema, so a take onto the older pin (v4.53.10-ls267) would start it on a database the newer build (ls269) already touched. - config is a pathless placed directory, mounted as ${dir:config} - a state directory placed at the assignment root carries route.json - image pinned to the digest ace runs today (v4.53.10-ls269) - the sidecar reaches ombi on the machine port the mesh assigns (${port:3579}) rather than assuming 3579 is free - the sidecar no longer mounts ombi's data directory: MESH_OMBI_CONFIG_DIR is read by no code, and the mount exposed the databases for nothing Verified: catalogue tests (MESH_CATALOGUE set, 6 pass, none skipped); the pinned image starts as PUID 1000 in a 0700 dir and answers /api/v1/Status 200; data owned 1001:2000 (ace's media ids) under a 1000:1000 dir is re-owned by the image's init and serves 200; a minted ApiKey is refused (401) - the api-key secret must be accepted from ombi's own settings.A host-network sidecar reaches its service over the machine's loopback, and the mesh publishes that service on a machine port it assigns (ADR 0038) — so dialling the software's port reaches whatever else holds it. On ace, searxng's sidecar dialled 127.0.0.1:8080 and got unifi's inform port. The same shape in bazarr, bookshelf, lidarr, nzbget, qbittorrent, radarr and sonarr; each now asks with ${port:N} (hq 088). Found in review of ace's module preparation.Superseded: this module now lives in novox/mesh-media-catalog (the media chain, consolidated from #145–#168 in stack order; its non-media parts merged via #195). Closing.
Pull request closed