The manifest named /services/nzbget/config and /var/lib/mesh/nzbget/config.json,
host paths ADR 0112 takes out of definitions. The config dir is now pathless
(${dir:config}); the runtime's config and route binding live in a placed state dir.
The image is pinned to v26.0-ls233, the digest ace runs. The old pin (v26.3-ls261)
is newer but unproven against ace's queue; moving up is a later, separate step.
The password own-secret reached the tools and nothing else, so a fresh machine ran
nzbget's well-known default while the tools held a minted value that matched
nothing. The server now reads it too, through the image's FILE__NZBGET_PASS (a
path in the environment, the value from a 0600 root file - ADR 0086), and both
restart on it. An adopted machine accepts its existing ControlPassword.
The tools assumed the control user is "nzbget"; they now read ControlUsername
from nzbget.conf on the read-only config mount (ace's is not "nzbget").
sonarr, radarr, lidarr and bookshelf reached nzbget by container name on HAL's
shared network. nzbget now provides nzbget-api (node scope: a download client
must share the consumer's download spool) and serves scheme, port, url-base and
username; the password is the operator-accepted pair credential, as for #156.
The web endpoint is routed (label nzbget). The runtime dials ${port:6789}, the
same line as #154.
Verified: catalogue tests with MESH_CATALOGUE set (not skipped); rendered for ace
with a pinned port and username setting; a throwaway of the pinned image on a
fresh 0700 dir with the secret as a 0600 root file answered the secret (200),
refused a wrong and the default password (401); the compiled client read the
username from nzbget.conf and reached version/status/queue/history; strict
typecheck and the module's Dockerfile build pass.
151 lines
3.2 KiB
JSON
151 lines
3.2 KiB
JSON
{
|
|
"module": "nzbget",
|
|
"version": "1",
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"emits": [
|
|
"download.added",
|
|
"download.completed"
|
|
],
|
|
"consumes": [],
|
|
"own-secrets": {
|
|
"broker": "/var/lib/mesh/nzbget/broker",
|
|
"password": "/var/lib/mesh/nzbget/password"
|
|
},
|
|
"listens": [
|
|
{
|
|
"name": "web",
|
|
"port": 6789,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the download client's pages, and the JSON-RPC API its consumers and its own tools call"
|
|
}
|
|
],
|
|
"accesses": [
|
|
{
|
|
"path": "/services/media/downloads",
|
|
"mode": "read-write"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"path": "/var/lib/mesh/nzbget",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "."
|
|
},
|
|
{
|
|
"id": "config",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"owner": "1000:1000"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "nzbget",
|
|
"image": "lscr.io/linuxserver/nzbget@sha256:ec3ef0ae7dc410084086a7fdd447deda4747531154aa1cc5c7c48ac60794e277",
|
|
"env": {
|
|
"PUID": "1000",
|
|
"PGID": "1000",
|
|
"TZ": "Etc/UTC",
|
|
"FILE__NZBGET_PASS": "/run/secrets/password"
|
|
},
|
|
"ports": [
|
|
"6789"
|
|
],
|
|
"volumes": [
|
|
"${dir:config}:/config",
|
|
"/services/media/downloads:/downloads",
|
|
"/var/lib/mesh/nzbget/password:/run/secrets/password:ro"
|
|
],
|
|
"restart-on": [
|
|
"needs-password"
|
|
]
|
|
},
|
|
{
|
|
"id": "runtime-config",
|
|
"type": "file",
|
|
"path": "${dir:state}/config.json",
|
|
"mode": "0600",
|
|
"content": "{}\n",
|
|
"merge": "json"
|
|
},
|
|
{
|
|
"id": "runtime",
|
|
"type": "container",
|
|
"name": "mesh-nzbget",
|
|
"network": "host",
|
|
"volumes": [
|
|
"/var/lib/mesh/nzbget/broker:/run/secrets/broker:ro",
|
|
"/var/lib/mesh/nzbget/password:/run/secrets/password:ro",
|
|
"${dir:state}/config.json:/run/config/config.json:ro",
|
|
"${dir:config}:/var/lib/nzbget/config:ro"
|
|
],
|
|
"env": {
|
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
"MESH_NZBGET_URL": "http://127.0.0.1:${port:6789}",
|
|
"MESH_NZBGET_PASSWORD_FILE": "/run/secrets/password",
|
|
"MESH_NZBGET_CONFIG_FILE": "/run/config/config.json",
|
|
"MESH_NZBGET_CONFIG_DIR": "/var/lib/nzbget/config"
|
|
},
|
|
"restart-on": [
|
|
"runtime-config",
|
|
"needs-password"
|
|
],
|
|
"artifact": "runtime"
|
|
}
|
|
],
|
|
"provides": [
|
|
"nzbget-api"
|
|
],
|
|
"serves": {
|
|
"nzbget-api": {
|
|
"scheme": "http",
|
|
"port": 6789,
|
|
"url-base": "",
|
|
"username": "nzbget"
|
|
}
|
|
},
|
|
"requires": [
|
|
"route"
|
|
],
|
|
"contributes": {
|
|
"route": {
|
|
"label": "nzbget",
|
|
"endpoint": "web"
|
|
}
|
|
},
|
|
"binds": {
|
|
"route": "${dir:state}/route.json"
|
|
},
|
|
"build": {
|
|
"on": [
|
|
{
|
|
"arg": "BUILD_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "build"
|
|
},
|
|
{
|
|
"arg": "RUNTIME_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "runtime"
|
|
}
|
|
],
|
|
"artifacts": [
|
|
{
|
|
"name": "runtime",
|
|
"kind": "image",
|
|
"from": "Dockerfile"
|
|
}
|
|
]
|
|
}
|
|
}
|