ombi: the runtime serves its watcher and tools, and its connections step is a run-once process (hq ADR 0198)

The mesh-ombi container and the mesh-ombi-connections step container go with the Dockerfile, build bases and bus credential. The step runs node on the bundle and reads the servarr and plex bindings and the API key where the mesh writes them; it still runs again when one changes.
This commit is contained in:
jochen
2026-10-04 00:45:22 +02:00
parent 9db000a07f
commit 9234ba0e94
2 changed files with 27 additions and 86 deletions
-27
View File
@@ -1,27 +0,0 @@
# ombi's runtime: the tool runtime, carrying this module's compiled code.
#
# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in
# the base images, published like any other artifact — which is what makes this buildable by the
# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that
# happens to have the siblings.
#
# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the
# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`.
ARG BUILD_BASE
ARG RUNTIME_BASE
FROM ${BUILD_BASE} AS build
WORKDIR /app/modules/ombi
COPY . .
RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts servarr/settings.ts plex/settings.ts connections/index.ts \
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
FROM ${RUNTIME_BASE}
COPY --from=build /app/modules/ombi/dist /app/modules/ombi/dist
# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a
# provider's provisioner runs its reconcile loop in the same process, with the broker connected —
# the convention novox/hq issues 060/061 settled.
ENV MESH_TOOL_MODULES=/app/modules/ombi/dist/index.js,/app/modules/ombi/dist/tools/index.js
# NOT dist/connections/index.js: that is a step the host runs to completion, named by the `connections`
# container's args as `mesh-tools run …` (novox/hq ADR 0052). Listed here it would run inside the
# serving sidecar too, and exit it.
+27 -59
View File
@@ -9,7 +9,6 @@
"request.approved"
],
"own-secrets": {
"broker": "${dir:mesh-state}/broker",
"api-key": "${dir:mesh-state}/api-key"
},
"listens": [
@@ -76,53 +75,21 @@
"content": "{}\n",
"merge": "json"
},
{
"id": "runtime",
"type": "container",
"name": "mesh-ombi",
"network": "host",
"volumes": [
"${dir:mesh-state}/broker:/run/secrets/broker:ro",
"${dir:mesh-state}/api-key:/run/secrets/api-key:ro",
"${dir:mesh-state}/config.json:/run/config/config.json:ro"
],
"env": {
"MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_OMBI_URL": "http://127.0.0.1:${port:3579}",
"MESH_OMBI_API_KEY_FILE": "/run/secrets/api-key",
"MESH_OMBI_CONFIG_FILE": "/run/config/config.json"
},
"restart-on": [
"runtime-config"
],
"artifact": "runtime"
},
{
"id": "connections",
"type": "container",
"name": "mesh-ombi-connections",
"network": "host",
"run-once": true,
"volumes": [
"${dir:mesh-state}/api-key:/run/secrets/api-key:ro",
"${dir:state}/sonarr-api.json:/run/connections/sonarr-api.json:ro",
"${dir:state}/sonarr-api.secret:/run/connections/sonarr-api.secret:ro",
"${dir:state}/radarr-api.json:/run/connections/radarr-api.json:ro",
"${dir:state}/radarr-api.secret:/run/connections/radarr-api.secret:ro",
"${dir:state}/lidarr-api.json:/run/connections/lidarr-api.json:ro",
"${dir:state}/lidarr-api.secret:/run/connections/lidarr-api.secret:ro",
"${dir:state}/plex-api.json:/run/connections/plex-api.json:ro",
"${dir:state}/plex-api.secret:/run/connections/plex-api.secret:ro"
"type": "process",
"name": "ombi-connections",
"artifact": "code",
"run": [
"node",
"connections/index.js"
],
"run-once": true,
"env": {
"MESH_OMBI_URL": "http://127.0.0.1:${port:3579}",
"MESH_OMBI_API_KEY_FILE": "/run/secrets/api-key",
"MESH_CONNECTIONS_DIR": "/run/connections"
"MESH_OMBI_API_KEY_FILE": "${dir:mesh-state}/api-key",
"MESH_CONNECTIONS_DIR": "${dir:state}"
},
"args": [
"run",
"/app/modules/ombi/dist/connections/index.js"
],
"restart-on": [
"bound-sonarr-api",
"secret-sonarr-api",
@@ -132,8 +99,7 @@
"secret-lidarr-api",
"bound-plex-api",
"secret-plex-api"
],
"artifact": "runtime"
]
}
],
"requires": [
@@ -163,23 +129,25 @@
"plex-api": "${dir:state}/plex-api.secret"
},
"build": {
"on": [
{
"arg": "BUILD_BASE",
"module": "mesh-tools",
"artifact": "build"
},
{
"arg": "RUNTIME_BASE",
"module": "mesh-tools",
"artifact": "runtime"
}
],
"artifacts": [
{
"name": "runtime",
"kind": "image",
"from": "Dockerfile"
"name": "code",
"kind": "bundle",
"language": "typescript",
"entrypoints": [
"index.js",
"tools/index.js",
"connections/index.js"
],
"loads": [
"index.js",
"tools/index.js"
],
"env": {
"MESH_OMBI_URL": "http://127.0.0.1:${port:3579}",
"MESH_OMBI_API_KEY_FILE": "${dir:mesh-state}/api-key",
"MESH_OMBI_CONFIG_FILE": "${dir:mesh-state}/config.json"
}
}
]
}