04-ISSUES/036: eight media modules each declared the shared library and download directories under /services/media/* as their own `directory` resources. Six of them owning one path is the collision the resolver refuses — so the stack's only sensible assignment, all on one machine sharing one filesystem, would be refused the first time two landed together. The media library is the operator's, owned by no module (novox/hq ADR 0051). Move every /services/media/* path from an owned `directory` resource to an `accesses` entry: the mesh mounts it and owns nothing — does not create, chown, reconcile or remove it — and several modules may access one path with no conflict. Each module's own config and mesh-state directories stay owned resources. Modes are least-privilege: plex reads the libraries it streams; the managers and download clients get read-write on what they import and write; bazarr writes subtitles into the libraries (read-write) and only reads the download spool. The container volume mounts are unchanged. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
89 lines
2.0 KiB
JSON
89 lines
2.0 KiB
JSON
{
|
|
"module": "sonarr",
|
|
"version": "1",
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"emits": [
|
|
"module.sonarr.episode.grabbed",
|
|
"module.sonarr.download.completed"
|
|
],
|
|
"consumes": [],
|
|
"own-secrets": {
|
|
"broker": "/var/lib/mesh/sonarr/broker"
|
|
},
|
|
"listens": [
|
|
{
|
|
"port": 8989,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "managing series"
|
|
}
|
|
],
|
|
"accesses": [
|
|
{
|
|
"path": "/services/media/series",
|
|
"mode": "read-write"
|
|
},
|
|
{
|
|
"path": "/services/media/anime",
|
|
"mode": "read-write"
|
|
},
|
|
{
|
|
"path": "/services/media/downloads",
|
|
"mode": "read-write"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh/sonarr",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "config",
|
|
"type": "directory",
|
|
"path": "/services/sonarr/config",
|
|
"mode": "0700",
|
|
"owner": "1000:1000"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "sonarr",
|
|
"image": "lscr.io/linuxserver/sonarr@sha256:c19aa4ecdf03d73e1d5c901da33744cb7eb4d921f89bafed1ca264601d7fa224",
|
|
"env": {
|
|
"PUID": "1000",
|
|
"PGID": "1000",
|
|
"TZ": "Etc/UTC"
|
|
},
|
|
"ports": [
|
|
"8989"
|
|
],
|
|
"volumes": [
|
|
"/services/sonarr/config:/config",
|
|
"/services/media/series:/series",
|
|
"/services/media/anime:/anime",
|
|
"/services/media/downloads:/downloads"
|
|
]
|
|
},
|
|
{
|
|
"id": "runtime",
|
|
"type": "container",
|
|
"name": "mesh-sonarr",
|
|
"image": "mesh-runtime-sonarr@sha256:0000000000000000000000000000000000000000000000000000000000000000",
|
|
"network": "host",
|
|
"volumes": [
|
|
"/var/lib/mesh/sonarr/broker:/run/secrets/broker:ro",
|
|
"/services/sonarr/config:/var/lib/sonarr/config:ro"
|
|
],
|
|
"env": {
|
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
"MESH_SONARR_URL": "http://127.0.0.1:8989",
|
|
"MESH_SONARR_CONFIG_DIR": "/var/lib/sonarr/config"
|
|
}
|
|
}
|
|
]
|
|
}
|