The mesh-icecast container goes with its Dockerfile, build bases and bus credential. The bundle reaches icecast on the port this machine published rather than the container network's name.
119 lines
4.7 KiB
JSON
119 lines
4.7 KiB
JSON
{
|
|
"module": "icecast",
|
|
"version": "1",
|
|
"requires": [
|
|
"route",
|
|
"secret"
|
|
],
|
|
"contributes": {
|
|
"route": {
|
|
"label": "icecast",
|
|
"endpoint": "stream"
|
|
}
|
|
},
|
|
"binds": {
|
|
"route": "${dir:state}/route.json"
|
|
},
|
|
"secrets": {
|
|
"secret": {
|
|
"source": "${dir:state}/source.secret",
|
|
"admin": "${dir:state}/admin.secret",
|
|
"relay": "${dir:state}/relay.secret"
|
|
}
|
|
},
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"emits": [
|
|
"stream.started",
|
|
"stream.stopped"
|
|
],
|
|
"listens": [
|
|
{
|
|
"name": "stream",
|
|
"port": 8000,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "streams in from sources (HTTP PUT) and out to listeners, plus the status and admin pages; a public name is its route"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "mesh"
|
|
},
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "."
|
|
},
|
|
{
|
|
"id": "logs",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"owner": "100:101"
|
|
},
|
|
{
|
|
"id": "server-conf",
|
|
"type": "file",
|
|
"path": "${dir:state}/icecast.xml",
|
|
"mode": "0600",
|
|
"content": "<icecast>\n <!-- Written by the mesh (modules/icecast). Passwords arrive as secrets rendered into this file,\n never as environment: the image's entrypoint seds ICECAST_* variables into the file only\n when they are set, and none are. -->\n <location>Earth</location>\n <admin>icemaster@localhost</admin>\n <limits>\n <clients>100</clients>\n <sources>2</sources>\n <queue-size>524288</queue-size>\n <client-timeout>30</client-timeout>\n <header-timeout>15</header-timeout>\n <source-timeout>10</source-timeout>\n <burst-on-connect>1</burst-on-connect>\n <burst-size>65535</burst-size>\n </limits>\n <authentication>\n <source-password>${secret:source}</source-password>\n <relay-password>${secret:relay}</relay-password>\n <admin-user>admin</admin-user>\n <admin-password>${secret:admin}</admin-password>\n </authentication>\n <!-- The name icecast writes into playlists (.m3u/.xspf: http://<hostname>:<port>/<mount>) and\n would announce to YP (none configured). A machine's own name belongs to its assignment, and\n an assignment merges only into JSON; this XML cannot take it, so the neutral default stays. -->\n <hostname>localhost</hostname>\n <listen-socket>\n <port>8000</port>\n </listen-socket>\n <http-headers>\n <header name=\"Access-Control-Allow-Origin\" value=\"*\" />\n </http-headers>\n <fileserve>1</fileserve>\n <paths>\n <basedir>/usr/share/icecast</basedir>\n <logdir>/var/log/icecast</logdir>\n <webroot>/usr/share/icecast/web</webroot>\n <adminroot>/usr/share/icecast/admin</adminroot>\n <alias source=\"/\" destination=\"/status.xsl\"/>\n </paths>\n <logging>\n <accesslog>access.log</accesslog>\n <errorlog>error.log</errorlog>\n <loglevel>3</loglevel>\n <logsize>10000</logsize>\n </logging>\n <security>\n <chroot>0</chroot>\n <!-- Starts as root, reads this 0600 root-owned file, then drops to the image's icecast user\n (uid 100, group icecast 101) before serving. -->\n <changeowner>\n <user>icecast</user>\n <group>icecast</group>\n </changeowner>\n </security>\n</icecast>\n"
|
|
},
|
|
{
|
|
"id": "net",
|
|
"type": "network",
|
|
"name": "icecast"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "icecast",
|
|
"image": "infiniteproject/icecast@sha256:cd506cf3dfe31ce05fd37d7e672dbd1213e7255cc93d28ecf5a3b547af4e162c",
|
|
"network": "icecast",
|
|
"ports": [
|
|
"8000"
|
|
],
|
|
"volumes": [
|
|
"${dir:state}/icecast.xml:/etc/icecast.xml:ro",
|
|
"${dir:logs}:/var/log/icecast"
|
|
],
|
|
"restart-on": [
|
|
"server-conf"
|
|
]
|
|
},
|
|
{
|
|
"id": "runtime-config",
|
|
"type": "file",
|
|
"path": "${dir:mesh-state}/config.json",
|
|
"mode": "0600",
|
|
"content": "{}\n",
|
|
"merge": "json"
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "code",
|
|
"kind": "bundle",
|
|
"language": "typescript",
|
|
"entrypoints": [
|
|
"index.js",
|
|
"tools/index.js"
|
|
],
|
|
"loads": [
|
|
"index.js",
|
|
"tools/index.js"
|
|
],
|
|
"env": {
|
|
"MESH_ICECAST_URL": "http://127.0.0.1:${port:8000}",
|
|
"MESH_ICECAST_CONFIG_FILE": "${dir:mesh-state}/config.json"
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|