nzbget: placed config, the build ace runs, its password a file, its API provided #167
Closed
mesh-admin
wants to merge 1 commits from
feat/nzbget-for-ace into main
pull from: feat/nzbget-for-ace
merge into: :main
:main
:fix/resolver-passes-the-dnssec-bit
:fix/mailu-admin-asks-the-machines-resolver
:fix/110-the-resolver-answers-a-container
:feat/qbittorrent-for-ace
:feat/servarr-api-provision
:feat/home-assistant-for-ace
:feat/tautulli-for-ace
:feat/bookshelf-for-ace
:feat/lidarr-for-ace
:feat/radarr-for-ace
:feat/sonarr-for-ace
:feat/kometa-for-ace
:feat/plex-for-ace
:fix/manifests-publish-software-ports
:feat/nzbget-for-ace
:feat/bazarr-for-ace
:fix/sidecars-dial-the-port-they-were-given
:feat/ombi-for-ace
:chore/remove-the-network-checker-module
:feat/a-network-checker-module
:feat/modules-name-their-endpoints
:fix/a-routed-module-listens-from-the-mesh
:fix/the-resolver-declares-both-protocols
:fix/sshd-declares-the-daemon-it-owns
:fix/fail2ban-bans-through-what-every-machine-has
:fix/fail2ban-declares-the-log-its-own-jail-reads
:fix/fail2ban-restarts-on-its-log-target
:fix/fail2ban-declares-where-it-logs
:feat/the-catalogue-hears-what-it-missed
:feat/the-catalogue-prepares-its-own-schema
:fix/the-catalogue-declares-the-event-it-emits
:feat/a-merge-rebuilds-what-it-changed
:fix/a-merge-older-than-the-watching-is-history
:fix/a-merge-announced-is-said
:fix/the-forge-watches-every-repository
:feat/the-forge-announces-every-merge
:feat/nats-serves-the-meshs-certificate
:fix/nats-declares-its-base
:feat/amqp-leaves-the-catalogue
:restore/broker-claim
:revert/broker-seat-claim
:fix/broker-seat-must-stay-held
:fix/go-126-base
:feat/nats-genesis
:feat/ssh-client-module
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Prepares nzbget for ace (conversion only — nothing assigned).
Changes
${dir:config}; runtime config + route binding in placedstatedirsha256:ec3ef0ae…); the old pin v26.3-ls261 is newer but unproven against ace's queuepasswordown-secret now reaches the server too:FILE__NZBGET_PASS=/run/secrets/password(lsio's file variable; value from the 0600 root file, ADR 0086); server and runtimerestart-on: needs-password. Before, a fresh machine ran nzbget's well-known default passwordclient.ts: control username read fromnzbget.conf(ControlUsername), not assumed "nzbget"nzbget-api(node scope) and servesscheme/port/url-base/username; password = operator-accepted pair credential (same model as #156)nzbget→web; runtime dials${port:6789}(identical line to #154)Verified: catalogue tests with MESH_CATALOGUE (not skipped); render for ace with
{"endpoints":{"web":{"port":6790,...}},"username":"luffy"}; throwaway of the pinned image: secret-file password → 200, wrong/default → 401; compiled client read the username from nzbget.conf and reached version/status/queue/history; strict tsc + Dockerfile build.Blocked for ace by hq 153: the downloads access path (ace:
/storage/downloads) and the run-as uid:gid (ace: 1001:2000) cannot be set per node yet. Do not assign on ace before 153.The manifest named /services/nzbget/config and /var/lib/mesh/nzbget/config.json, host paths ADR 0112 takes out of definitions. The config dir is now pathless (${dir:config}); the runtime's config and route binding live in a placed state dir. The image is pinned to v26.0-ls233, the digest ace runs. The old pin (v26.3-ls261) is newer but unproven against ace's queue; moving up is a later, separate step. The password own-secret reached the tools and nothing else, so a fresh machine ran nzbget's well-known default while the tools held a minted value that matched nothing. The server now reads it too, through the image's FILE__NZBGET_PASS (a path in the environment, the value from a 0600 root file - ADR 0086), and both restart on it. An adopted machine accepts its existing ControlPassword. The tools assumed the control user is "nzbget"; they now read ControlUsername from nzbget.conf on the read-only config mount (ace's is not "nzbget"). sonarr, radarr, lidarr and bookshelf reached nzbget by container name on HAL's shared network. nzbget now provides nzbget-api (node scope: a download client must share the consumer's download spool) and serves scheme, port, url-base and username; the password is the operator-accepted pair credential, as for #156. The web endpoint is routed (label nzbget). The runtime dials ${port:6789}, the same line as #154. Verified: catalogue tests with MESH_CATALOGUE set (not skipped); rendered for ace with a pinned port and username setting; a throwaway of the pinned image on a fresh 0700 dir with the secret as a 0600 root file answered the secret (200), refused a wrong and the default password (401); the compiled client read the username from nzbget.conf and reached version/status/queue/history; strict typecheck and the module's Dockerfile build pass.Superseded: this module now lives in novox/mesh-media-catalog (the media chain, consolidated from #145–#168 in stack order; its non-media parts merged via #195). Closing.
Pull request closed