module fixes from the whole-mesh dry-run: fail2ban capability + tool-runtime credential wiring #20
@@ -43,6 +43,14 @@ function meshConfig(file?: string): Record<string, string> {
|
||||
catch { return {}; }
|
||||
}
|
||||
|
||||
/** Read a secret the mesh mounted at a file path (an own-secret delivered by `secret accept`);
|
||||
* absent or unreadable yields undefined so callers fall back rather than crash. */
|
||||
function readSecret(file?: string): string | undefined {
|
||||
if (!file) return undefined;
|
||||
try { return readFileSync(file, "utf8").trim(); }
|
||||
catch { return undefined; }
|
||||
}
|
||||
|
||||
export class BazarrClient {
|
||||
readonly baseUrl: string;
|
||||
|
||||
@@ -58,7 +66,7 @@ export class BazarrClient {
|
||||
static fromEnv(env: NodeJS.ProcessEnv = process.env): BazarrClient {
|
||||
const cfg = meshConfig(env.MESH_BAZARR_CONFIG_FILE);
|
||||
const url = cfg.url ?? env.MESH_BAZARR_URL;
|
||||
const apiKey = cfg.apiKey ?? env.MESH_BAZARR_API_KEY;
|
||||
const apiKey = cfg.apiKey ?? readSecret(env.MESH_BAZARR_API_KEY_FILE) ?? env.MESH_BAZARR_API_KEY;
|
||||
if (!url) throw new Error("no Bazarr URL — set MESH_BAZARR_URL");
|
||||
if (!apiKey) throw new Error("no Bazarr API key — set MESH_BAZARR_API_KEY");
|
||||
return new BazarrClient(url, apiKey);
|
||||
|
||||
@@ -8,7 +8,8 @@
|
||||
"module.bazarr.subtitle.downloaded"
|
||||
],
|
||||
"own-secrets": {
|
||||
"broker": "/var/lib/mesh/bazarr/broker"
|
||||
"broker": "/var/lib/mesh/bazarr/broker",
|
||||
"api-key": "/var/lib/mesh/bazarr/api-key"
|
||||
},
|
||||
"listens": [
|
||||
{
|
||||
@@ -87,12 +88,14 @@
|
||||
"network": "host",
|
||||
"volumes": [
|
||||
"/var/lib/mesh/bazarr/broker:/run/secrets/broker:ro",
|
||||
"/var/lib/mesh/bazarr/api-key:/run/secrets/api-key:ro",
|
||||
"/var/lib/mesh/bazarr/config.json:/run/config/config.json:ro",
|
||||
"/services/bazarr/config:/var/lib/bazarr/config:ro"
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_BAZARR_URL": "http://127.0.0.1:6767",
|
||||
"MESH_BAZARR_API_KEY_FILE": "/run/secrets/api-key",
|
||||
"MESH_BAZARR_CONFIG_FILE": "/run/config/config.json",
|
||||
"MESH_BAZARR_CONFIG_DIR": "/var/lib/bazarr/config"
|
||||
},
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
"module": "fail2ban",
|
||||
"version": "1",
|
||||
"capabilities": [
|
||||
"intrusion-prevention"
|
||||
"firewall"
|
||||
],
|
||||
"claims": [
|
||||
{
|
||||
|
||||
@@ -27,6 +27,14 @@ function meshConfig(file?: string): Record<string, string> {
|
||||
catch { return {}; }
|
||||
}
|
||||
|
||||
/** Read a secret the mesh mounted at a file path (an own-secret delivered by `secret accept`);
|
||||
* absent or unreadable yields undefined so callers fall back rather than crash. */
|
||||
function readSecret(file?: string): string | undefined {
|
||||
if (!file) return undefined;
|
||||
try { return readFileSync(file, "utf8").trim(); }
|
||||
catch { return undefined; }
|
||||
}
|
||||
|
||||
export class HomeAssistantClient {
|
||||
readonly baseUrl: string;
|
||||
|
||||
@@ -45,7 +53,7 @@ export class HomeAssistantClient {
|
||||
static fromEnv(env: NodeJS.ProcessEnv = process.env): HomeAssistantClient {
|
||||
const cfg = meshConfig(env.MESH_HOMEASSISTANT_CONFIG_FILE);
|
||||
const url = cfg.url ?? env.MESH_HOMEASSISTANT_URL ?? `http://127.0.0.1:${env.HOMEASSISTANT_PORT ?? "8123"}`;
|
||||
const token = cfg.token ?? env.MESH_HOMEASSISTANT_TOKEN;
|
||||
const token = cfg.token ?? readSecret(env.MESH_HOMEASSISTANT_TOKEN_FILE) ?? env.MESH_HOMEASSISTANT_TOKEN;
|
||||
if (!token) throw new Error("no Home Assistant token — set MESH_HOMEASSISTANT_TOKEN");
|
||||
return new HomeAssistantClient(url, token);
|
||||
}
|
||||
|
||||
@@ -8,7 +8,8 @@
|
||||
"module.home-assistant.state.changed"
|
||||
],
|
||||
"own-secrets": {
|
||||
"broker": "/var/lib/mesh/home-assistant/broker"
|
||||
"broker": "/var/lib/mesh/home-assistant/broker",
|
||||
"token": "/var/lib/mesh/home-assistant/token"
|
||||
},
|
||||
"listens": [
|
||||
{
|
||||
@@ -61,12 +62,14 @@
|
||||
"network": "host",
|
||||
"volumes": [
|
||||
"/var/lib/mesh/home-assistant/broker:/run/secrets/broker:ro",
|
||||
"/var/lib/mesh/home-assistant/token:/run/secrets/token:ro",
|
||||
"/var/lib/mesh/home-assistant/config.json:/run/config/config.json:ro",
|
||||
"/services/home-assistant/config:/var/lib/home-assistant/config:ro"
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_HOMEASSISTANT_URL": "http://127.0.0.1:8123",
|
||||
"MESH_HOMEASSISTANT_TOKEN_FILE": "/run/secrets/token",
|
||||
"MESH_HOMEASSISTANT_CONFIG_FILE": "/run/config/config.json",
|
||||
"MESH_HOMEASSISTANT_CONFIG_DIR": "/var/lib/home-assistant/config"
|
||||
},
|
||||
|
||||
@@ -48,6 +48,14 @@ function meshConfig(file?: string): Record<string, string> {
|
||||
catch { return {}; }
|
||||
}
|
||||
|
||||
/** Read a secret the mesh mounted at a file path (an own-secret delivered by `secret accept`);
|
||||
* absent or unreadable yields undefined so callers fall back rather than crash. */
|
||||
function readSecret(file?: string): string | undefined {
|
||||
if (!file) return undefined;
|
||||
try { return readFileSync(file, "utf8").trim(); }
|
||||
catch { return undefined; }
|
||||
}
|
||||
|
||||
export class NzbgetClient {
|
||||
readonly rpcUrl: string;
|
||||
private readonly auth: string;
|
||||
@@ -66,7 +74,7 @@ export class NzbgetClient {
|
||||
static fromEnv(env: NodeJS.ProcessEnv = process.env): NzbgetClient {
|
||||
const cfg = meshConfig(env.MESH_NZBGET_CONFIG_FILE);
|
||||
const url = cfg.url ?? env.MESH_NZBGET_URL;
|
||||
const password = cfg.password ?? env.MESH_NZBGET_PASSWORD;
|
||||
const password = cfg.password ?? readSecret(env.MESH_NZBGET_PASSWORD_FILE) ?? env.MESH_NZBGET_PASSWORD;
|
||||
if (!url || !password) {
|
||||
throw new Error("NZBGet not configured — set MESH_NZBGET_URL and MESH_NZBGET_PASSWORD");
|
||||
}
|
||||
|
||||
@@ -10,7 +10,8 @@
|
||||
],
|
||||
"consumes": [],
|
||||
"own-secrets": {
|
||||
"broker": "/var/lib/mesh/nzbget/broker"
|
||||
"broker": "/var/lib/mesh/nzbget/broker",
|
||||
"password": "/var/lib/mesh/nzbget/password"
|
||||
},
|
||||
"listens": [
|
||||
{
|
||||
@@ -74,12 +75,14 @@
|
||||
"network": "host",
|
||||
"volumes": [
|
||||
"/var/lib/mesh/nzbget/broker:/run/secrets/broker:ro",
|
||||
"/var/lib/mesh/nzbget/password:/run/secrets/password:ro",
|
||||
"/var/lib/mesh/nzbget/config.json:/run/config/config.json:ro",
|
||||
"/services/nzbget/config:/var/lib/nzbget/config:ro"
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_NZBGET_URL": "http://127.0.0.1:6789",
|
||||
"MESH_NZBGET_PASSWORD_FILE": "/run/secrets/password",
|
||||
"MESH_NZBGET_CONFIG_FILE": "/run/config/config.json",
|
||||
"MESH_NZBGET_CONFIG_DIR": "/var/lib/nzbget/config"
|
||||
},
|
||||
|
||||
@@ -29,6 +29,14 @@ function meshConfig(file?: string): Record<string, string> {
|
||||
catch { return {}; }
|
||||
}
|
||||
|
||||
/** Read a secret the mesh mounted at a file path (an own-secret delivered by `secret accept`);
|
||||
* absent or unreadable yields undefined so callers fall back rather than crash. */
|
||||
function readSecret(file?: string): string | undefined {
|
||||
if (!file) return undefined;
|
||||
try { return readFileSync(file, "utf8").trim(); }
|
||||
catch { return undefined; }
|
||||
}
|
||||
|
||||
export class OmbiClient {
|
||||
readonly baseUrl: string;
|
||||
|
||||
@@ -44,7 +52,7 @@ export class OmbiClient {
|
||||
static fromEnv(env: NodeJS.ProcessEnv = process.env): OmbiClient {
|
||||
const cfg = meshConfig(env.MESH_OMBI_CONFIG_FILE);
|
||||
const url = cfg.url ?? env.MESH_OMBI_URL;
|
||||
const apiKey = cfg.apiKey ?? env.MESH_OMBI_API_KEY;
|
||||
const apiKey = cfg.apiKey ?? readSecret(env.MESH_OMBI_API_KEY_FILE) ?? env.MESH_OMBI_API_KEY;
|
||||
if (!url) throw new Error("no Ombi URL — set MESH_OMBI_URL");
|
||||
if (!apiKey) throw new Error("no Ombi API key — set MESH_OMBI_API_KEY");
|
||||
return new OmbiClient(url, apiKey);
|
||||
|
||||
@@ -9,7 +9,8 @@
|
||||
"module.ombi.request.approved"
|
||||
],
|
||||
"own-secrets": {
|
||||
"broker": "/var/lib/mesh/ombi/broker"
|
||||
"broker": "/var/lib/mesh/ombi/broker",
|
||||
"api-key": "/var/lib/mesh/ombi/api-key"
|
||||
},
|
||||
"listens": [
|
||||
{
|
||||
@@ -66,12 +67,14 @@
|
||||
"network": "host",
|
||||
"volumes": [
|
||||
"/var/lib/mesh/ombi/broker:/run/secrets/broker:ro",
|
||||
"/var/lib/mesh/ombi/api-key:/run/secrets/api-key:ro",
|
||||
"/var/lib/mesh/ombi/config.json:/run/config/config.json:ro",
|
||||
"/services/ombi/config:/var/lib/ombi/config:ro"
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_OMBI_URL": "http://127.0.0.1:3579",
|
||||
"MESH_OMBI_API_KEY_FILE": "/run/secrets/api-key",
|
||||
"MESH_OMBI_CONFIG_FILE": "/run/config/config.json",
|
||||
"MESH_OMBI_CONFIG_DIR": "/var/lib/ombi/config"
|
||||
},
|
||||
|
||||
+14
-1
@@ -5,6 +5,17 @@
|
||||
import { existsSync, readFileSync } from "node:fs";
|
||||
import { join } from "node:path";
|
||||
|
||||
/** Read a secret the mesh mounted at a file path (an own-secret); absent or unreadable yields
|
||||
* undefined, so callers can fall back rather than crash. */
|
||||
function readSecret(path: string | undefined): string | undefined {
|
||||
if (!path) return undefined;
|
||||
try {
|
||||
return readFileSync(path, "utf8").trim();
|
||||
} catch {
|
||||
return undefined;
|
||||
}
|
||||
}
|
||||
|
||||
export interface PlexLibrary {
|
||||
key: string;
|
||||
title: string;
|
||||
@@ -47,7 +58,9 @@ export class PlexClient {
|
||||
static fromEnv(env: NodeJS.ProcessEnv = process.env): PlexClient {
|
||||
const url = env.MESH_PLEX_URL ?? `http://127.0.0.1:${env.PLEX_PORT ?? "32400"}`;
|
||||
const dataDir = env.MESH_PLEX_DATA_DIR ?? "/var/lib/plex";
|
||||
const token = env.MESH_PLEX_TOKEN ?? PlexClient.detectToken(dataDir);
|
||||
// The operator-provided token is an own-secret the mesh mounts at MESH_PLEX_TOKEN_FILE (delivered
|
||||
// by `secret accept`); prefer it, fall back to a bare env var, then to discovery from the data dir.
|
||||
const token = readSecret(env.MESH_PLEX_TOKEN_FILE) ?? env.MESH_PLEX_TOKEN ?? PlexClient.detectToken(dataDir);
|
||||
if (!token) throw new Error("no Plex token — set MESH_PLEX_TOKEN or make the data dir readable");
|
||||
return new PlexClient(url, token);
|
||||
}
|
||||
|
||||
@@ -13,7 +13,8 @@
|
||||
"module.*.download.completed"
|
||||
],
|
||||
"own-secrets": {
|
||||
"broker": "/var/lib/mesh/plex/broker"
|
||||
"broker": "/var/lib/mesh/plex/broker",
|
||||
"token": "/var/lib/mesh/plex/token"
|
||||
},
|
||||
"listens": [
|
||||
{
|
||||
@@ -95,11 +96,13 @@
|
||||
"network": "host",
|
||||
"volumes": [
|
||||
"/var/lib/mesh/plex/broker:/run/secrets/broker:ro",
|
||||
"/var/lib/mesh/plex/token:/run/secrets/token:ro",
|
||||
"/services/plex/config:/var/lib/plex/config:ro"
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_PLEX_URL": "http://127.0.0.1:32400",
|
||||
"MESH_PLEX_TOKEN_FILE": "/run/secrets/token",
|
||||
"MESH_PLEX_DATA_DIR": "/var/lib/plex"
|
||||
}
|
||||
}
|
||||
|
||||
@@ -39,6 +39,14 @@ function meshConfig(file?: string): Record<string, string> {
|
||||
catch { return {}; }
|
||||
}
|
||||
|
||||
/** Read a secret the mesh mounted at a file path (an own-secret delivered by `secret accept`);
|
||||
* absent or unreadable yields undefined so callers fall back rather than crash. */
|
||||
function readSecret(file?: string): string | undefined {
|
||||
if (!file) return undefined;
|
||||
try { return readFileSync(file, "utf8").trim(); }
|
||||
catch { return undefined; }
|
||||
}
|
||||
|
||||
export class QbittorrentClient {
|
||||
readonly baseUrl: string;
|
||||
private sid: string | null = null;
|
||||
@@ -60,7 +68,7 @@ export class QbittorrentClient {
|
||||
static fromEnv(env: NodeJS.ProcessEnv = process.env): QbittorrentClient {
|
||||
const cfg = meshConfig(env.MESH_QBITTORRENT_CONFIG_FILE);
|
||||
const url = cfg.url ?? env.MESH_QBITTORRENT_URL;
|
||||
const password = cfg.password ?? env.MESH_QBITTORRENT_PASSWORD;
|
||||
const password = cfg.password ?? readSecret(env.MESH_QBITTORRENT_PASSWORD_FILE) ?? env.MESH_QBITTORRENT_PASSWORD;
|
||||
if (!url || !password) {
|
||||
throw new Error("qBittorrent not configured — set MESH_QBITTORRENT_URL and MESH_QBITTORRENT_PASSWORD");
|
||||
}
|
||||
|
||||
@@ -10,7 +10,8 @@
|
||||
],
|
||||
"consumes": [],
|
||||
"own-secrets": {
|
||||
"broker": "/var/lib/mesh/qbittorrent/broker"
|
||||
"broker": "/var/lib/mesh/qbittorrent/broker",
|
||||
"password": "/var/lib/mesh/qbittorrent/password"
|
||||
},
|
||||
"listens": [
|
||||
{
|
||||
@@ -74,12 +75,14 @@
|
||||
"network": "host",
|
||||
"volumes": [
|
||||
"/var/lib/mesh/qbittorrent/broker:/run/secrets/broker:ro",
|
||||
"/var/lib/mesh/qbittorrent/password:/run/secrets/password:ro",
|
||||
"/var/lib/mesh/qbittorrent/config.json:/run/config/config.json:ro",
|
||||
"/services/qbittorrent/config:/var/lib/qbittorrent/config:ro"
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_QBITTORRENT_URL": "http://127.0.0.1:8080",
|
||||
"MESH_QBITTORRENT_PASSWORD_FILE": "/run/secrets/password",
|
||||
"MESH_QBITTORRENT_CONFIG_FILE": "/run/config/config.json",
|
||||
"MESH_QBITTORRENT_CONFIG_DIR": "/var/lib/qbittorrent/config"
|
||||
},
|
||||
|
||||
+13
-1
@@ -2,6 +2,18 @@
|
||||
// changes when umami's API does (novox/hq ADR 0039). Both this module's tools and its provisioner
|
||||
// import it; nothing outside umami does.
|
||||
|
||||
import { readFileSync } from "node:fs";
|
||||
|
||||
/** Read a secret from the file the mesh mounted it at, if the pointing env is set. */
|
||||
function readSecret(path: string | undefined): string | undefined {
|
||||
if (!path) return undefined;
|
||||
try {
|
||||
return readFileSync(path, "utf8").trim() || undefined;
|
||||
} catch {
|
||||
return undefined;
|
||||
}
|
||||
}
|
||||
|
||||
export interface Website {
|
||||
id: string;
|
||||
name: string;
|
||||
@@ -23,7 +35,7 @@ export class UmamiClient {
|
||||
static fromEnv(env: NodeJS.ProcessEnv = process.env): UmamiClient {
|
||||
const url = env.MESH_PROVISION_UMAMI_URL ?? env.UMAMI_URL;
|
||||
const username = env.UMAMI_USERNAME ?? "admin";
|
||||
const password = env.UMAMI_ADMIN_PASSWORD;
|
||||
const password = readSecret(env.MESH_UMAMI_ADMIN_PASSWORD_FILE) ?? env.UMAMI_ADMIN_PASSWORD;
|
||||
if (!url || !password) {
|
||||
throw new Error("UMAMI url or admin password is not set — umami's own code cannot reach it");
|
||||
}
|
||||
|
||||
@@ -110,7 +110,8 @@
|
||||
],
|
||||
"env": {
|
||||
"MESH_BROKER_FILE": "/run/secrets/broker",
|
||||
"MESH_RECEIVES": "/var/lib/umami/grants/mesh.json"
|
||||
"MESH_RECEIVES": "/var/lib/umami/grants/mesh.json",
|
||||
"MESH_UMAMI_ADMIN_PASSWORD_FILE": "/run/secrets/admin"
|
||||
},
|
||||
"env-file": [
|
||||
"/var/lib/umami/provisioner.env"
|
||||
|
||||
Reference in New Issue
Block a user