5 Commits
Author SHA1 Message Date
jochen 3fbe40c3ec bazarr, tautulli: read the app's own key through its container
Moved out of their containers, their code runs as the node runtime's account, which may not read
the app's config directory: it belongs to the account the app runs as on that machine, mode 0700.
Read the file directly when allowed, else through the app's own container, which owns it.
2026-10-04 01:09:54 +02:00
jochen 9db000a07f bazarr: the runtime serves its watcher and tools, and its servarr step is a run-once process (hq ADR 0198)
The mesh-bazarr container and the mesh-bazarr-servarr step container go with the Dockerfile, build bases, bus credential and state directory. The step runs node on the bundle and reads the sonarr and radarr bindings where the mesh writes them; it still runs again when one changes.
2026-10-04 00:45:22 +02:00
jschoubben 52abeb34bd The identity a module runs as is the assignment's, not the definition's
PUID/PGID (PLEX_UID/PLEX_GID for plex) were 1000:1000 in every definition —
one machine's fact written where it is true of no other (ADR 0112). Each
module now renders identity.env from ${setting:puid} and ${setting:pgid};
the mesh-wide layer carries the image's default, a node whose data belongs
to somebody else says so. An adopted machine's library must never be
re-owned (ace: 1001:2000, hq 153).
2026-10-01 00:35:07 +02:00
jschoubben c1ebc5a961 The media catalogue places the mesh's files and names its accesses (issues 174, 153)
Twelve definitions stop naming /var/lib/mesh/<module>: the directory says `place: "mesh"` (kometa
gains the directory it never declared), and every credential and mount names it as
${dir:mesh-state}. Every access has an id, kept beside its path as the default an assignment may
replace, and the host side of every mount says ${access:<id>} — so a home server's assignment can
say `accesses: {series: "/storage/media/series", …}` and `places: {config: {path: …, owner: …}}`
and the mounts follow. Resolved with no placement, eleven converted definitions name exactly the
paths they named before (TestPlacedDirectoriesKeepTheirPaths over both checkouts); kometa's added
directory is where the mesh already writes.

Needs the controller from mesh-controller #175/#176, running since 2026-10-01 00:06.
2026-10-01 00:27:27 +02:00
jschoubben db3adfa4c6 The media chain as mesh modules, in one catalogue
sonarr, radarr, lidarr, bazarr, nzbget, qbittorrent, jackett, bookshelf,
plex, tautulli, kometa and ombi, taken from the novox/mesh-catalog branches
that prepared them for ace (PRs 145-168), consolidated in stack order.
kometa gains a minimal runtime sidecar (kometa_status, kometa_config) and
declares its tmdb key as an own secret instead of a "secret" requirement.
2026-09-30 21:32:59 +02:00