Three more: nodered, icecast, portainer

Node-RED and Icecast are the plain shapes — a data directory owned by
the number inside, generated passwords in a host-written env file, one
declared port each.

Portainer mounts the container runtime's socket, which is the mount
04-ISSUES/026 is reopened about: a machine facility, not the module's
data, spelled today exactly like a data directory. It is converted as
it runs now rather than held hostage to that vocabulary — the same
mount the builder already carries — and it will be the second citation
when 026 gets its answer.

Letta stays unconverted for now: the arrangement being replaced pins a
year-old image of a fast-moving project, and converting a pin nobody
would keep is not fidelity. It wants a fresh look at what version to
run, which is a decision and not a translation.

All pinned by real digests, resolved on this workstation today.
This commit is contained in:
2026-09-02 02:08:33 +02:00
parent 1c4e10e0d8
commit d278edabe0
3 changed files with 122 additions and 0 deletions
+47
View File
@@ -0,0 +1,47 @@
{
"module": "icecast",
"version": "1",
"capabilities": [
"container-runtime"
],
"own-secrets": {
"source": "/var/lib/icecast-module/source.secret",
"admin": "/var/lib/icecast-module/admin.secret",
"relay": "/var/lib/icecast-module/relay.secret"
},
"listens": [
{
"port": 8000,
"protocol": "tcp",
"from": "mesh",
"why": "streams in from sources and out to listeners"
}
],
"resources": [
{
"id": "state",
"type": "directory",
"path": "/var/lib/icecast-module",
"mode": "0700"
},
{
"id": "server-env",
"type": "file",
"path": "/var/lib/icecast-module/server.env",
"mode": "0600",
"content": "ICECAST_SOURCE_PASSWORD=${secret:source}\nICECAST_ADMIN_PASSWORD=${secret:admin}\nICECAST_RELAY_PASSWORD=${secret:relay}\nICECAST_ADMIN_USERNAME=admin\n"
},
{
"id": "server",
"type": "container",
"name": "icecast",
"image": "infiniteproject/icecast@sha256:cd506cf3dfe31ce05fd37d7e672dbd1213e7255cc93d28ecf5a3b547af4e162c",
"env-file": [
"/var/lib/icecast-module/server.env"
],
"ports": [
"8000"
]
}
]
}
+39
View File
@@ -0,0 +1,39 @@
{
"module": "nodered",
"version": "1",
"capabilities": [
"container-runtime"
],
"listens": [
{
"port": 1880,
"protocol": "tcp",
"from": "mesh",
"why": "the flow editor and the endpoints flows expose"
}
],
"resources": [
{
"id": "data",
"type": "directory",
"path": "/services/nodered/data",
"mode": "0700",
"owner": "1000:1000"
},
{
"id": "server",
"type": "container",
"name": "nodered",
"image": "nodered/node-red@sha256:02a2b92a41b73d2bc388238b86e4fcaab7fb5466373adb24e1df6aa5845265ff",
"env": {
"TZ": "Etc/UTC"
},
"ports": [
"1880"
],
"volumes": [
"/services/nodered/data:/data"
]
}
]
}
+36
View File
@@ -0,0 +1,36 @@
{
"module": "portainer",
"version": "1",
"capabilities": [
"container-runtime"
],
"listens": [
{
"port": 9443,
"protocol": "tcp",
"from": "mesh",
"why": "the container dashboard, over its own tls"
}
],
"resources": [
{
"id": "data",
"type": "directory",
"path": "/services/portainer/data",
"mode": "0700"
},
{
"id": "server",
"type": "container",
"name": "portainer",
"image": "portainer/portainer-ce@sha256:511f3f06c96fe3b993ebeaafde311c1959cae73a7ef825dba6397d51b450dffa",
"ports": [
"9443"
],
"volumes": [
"/services/portainer/data:/data",
"/var/run/docker.sock:/var/run/docker.sock"
]
}
]
}