nzbget: placed config, the build ace runs, its password a file, its API provided #167

Closed
mesh-admin wants to merge 1 commits from feat/nzbget-for-ace into main
Contributor

Prepares nzbget for ace (conversion only — nothing assigned).

Changes

  • config dir pathless ${dir:config}; runtime config + route binding in placed state dir
  • image pinned to the digest ace runs, v26.0-ls233 (sha256:ec3ef0ae…); the old pin v26.3-ls261 is newer but unproven against ace's queue
  • password own-secret now reaches the server too: FILE__NZBGET_PASS=/run/secrets/password (lsio's file variable; value from the 0600 root file, ADR 0086); server and runtime restart-on: needs-password. Before, a fresh machine ran nzbget's well-known default password
  • client.ts: control username read from nzbget.conf (ControlUsername), not assumed "nzbget"
  • provides nzbget-api (node scope) and serves scheme/port/url-base/username; password = operator-accepted pair credential (same model as #156)
  • route contribution nzbget → web; runtime dials ${port:6789} (identical line to #154)

Verified: catalogue tests with MESH_CATALOGUE (not skipped); render for ace with {"endpoints":{"web":{"port":6790,...}},"username":"luffy"}; throwaway of the pinned image: secret-file password → 200, wrong/default → 401; compiled client read the username from nzbget.conf and reached version/status/queue/history; strict tsc + Dockerfile build.

Blocked for ace by hq 153: the downloads access path (ace: /storage/downloads) and the run-as uid:gid (ace: 1001:2000) cannot be set per node yet. Do not assign on ace before 153.

Prepares nzbget for ace (conversion only — nothing assigned). **Changes** - config dir pathless `${dir:config}`; runtime config + route binding in placed `state` dir - image pinned to the digest ace runs, v26.0-ls233 (`sha256:ec3ef0ae…`); the old pin v26.3-ls261 is newer but unproven against ace's queue - `password` own-secret now reaches the server too: `FILE__NZBGET_PASS=/run/secrets/password` (lsio's file variable; value from the 0600 root file, ADR 0086); server and runtime `restart-on: needs-password`. Before, a fresh machine ran nzbget's well-known default password - `client.ts`: control username read from `nzbget.conf` (`ControlUsername`), not assumed "nzbget" - provides `nzbget-api` (node scope) and serves `scheme/port/url-base/username`; password = operator-accepted pair credential (same model as #156) - route contribution `nzbget` → `web`; runtime dials `${port:6789}` (identical line to #154) **Verified**: catalogue tests with MESH_CATALOGUE (not skipped); render for ace with `{"endpoints":{"web":{"port":6790,...}},"username":"luffy"}`; throwaway of the pinned image: secret-file password → 200, wrong/default → 401; compiled client read the username from nzbget.conf and reached version/status/queue/history; strict tsc + Dockerfile build. **Blocked for ace by hq 153**: the downloads access path (ace: `/storage/downloads`) and the run-as uid:gid (ace: 1001:2000) cannot be set per node yet. Do not assign on ace before 153.
mesh-admin added 1 commit 2026-09-30 10:00:53 +00:00
The manifest named /services/nzbget/config and /var/lib/mesh/nzbget/config.json,
host paths ADR 0112 takes out of definitions. The config dir is now pathless
(${dir:config}); the runtime's config and route binding live in a placed state dir.

The image is pinned to v26.0-ls233, the digest ace runs. The old pin (v26.3-ls261)
is newer but unproven against ace's queue; moving up is a later, separate step.

The password own-secret reached the tools and nothing else, so a fresh machine ran
nzbget's well-known default while the tools held a minted value that matched
nothing. The server now reads it too, through the image's FILE__NZBGET_PASS (a
path in the environment, the value from a 0600 root file - ADR 0086), and both
restart on it. An adopted machine accepts its existing ControlPassword.

The tools assumed the control user is "nzbget"; they now read ControlUsername
from nzbget.conf on the read-only config mount (ace's is not "nzbget").

sonarr, radarr, lidarr and bookshelf reached nzbget by container name on HAL's
shared network. nzbget now provides nzbget-api (node scope: a download client
must share the consumer's download spool) and serves scheme, port, url-base and
username; the password is the operator-accepted pair credential, as for #156.
The web endpoint is routed (label nzbget). The runtime dials ${port:6789}, the
same line as #154.

Verified: catalogue tests with MESH_CATALOGUE set (not skipped); rendered for ace
with a pinned port and username setting; a throwaway of the pinned image on a
fresh 0700 dir with the secret as a 0600 root file answered the secret (200),
refused a wrong and the default password (401); the compiled client read the
username from nzbget.conf and reached version/status/queue/history; strict
typecheck and the module's Dockerfile build pass.
Author
Contributor

Superseded: this module now lives in novox/mesh-media-catalog (the media chain, consolidated from #145–#168 in stack order; its non-media parts merged via #195). Closing.

Superseded: this module now lives in novox/mesh-media-catalog (the media chain, consolidated from #145–#168 in stack order; its non-media parts merged via #195). Closing.
mesh-admin closed this pull request 2026-09-30 19:45:27 +00:00

Pull request closed

Please reopen this pull request to perform a merge.
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#167