The mesh-tautulli container and the mesh-tautulli-plex step container go with the Dockerfile, build bases and bus credential. The step runs node on the bundle and reads the plex binding where the mesh writes it; it still runs again when the server or the binding changes.
The mesh-ombi container and the mesh-ombi-connections step container go with the Dockerfile, build bases and bus credential. The step runs node on the bundle and reads the servarr and plex bindings and the API key where the mesh writes them; it still runs again when one changes.
The mesh-bazarr container and the mesh-bazarr-servarr step container go with the Dockerfile, build bases, bus credential and state directory. The step runs node on the bundle and reads the sonarr and radarr bindings where the mesh writes them; it still runs again when one changes.
The mesh-bookshelf container and the mesh-bookshelf-downloads step container go with the Dockerfile, build bases and bus credential. The step runs node on the bundle with its words in the process's env, the bound clients' files, the app's config.xml and its memory read where the mesh writes them; it still runs again when a binding it reads changes.
The mesh-lidarr container and the mesh-lidarr-downloads step container go with the Dockerfile, build bases and bus credential. The step runs node on the bundle with its words in the process's env, the bound clients' files, the app's config.xml and its memory read where the mesh writes them; it still runs again when a binding it reads changes.
The mesh-radarr container and the mesh-radarr-downloads step container go with the Dockerfile, build bases and bus credential. The step runs node on the bundle with its words in the process's env, the bound clients' files, the app's config.xml and its memory read where the mesh writes them; it still runs again when a binding it reads changes.
The mesh-sonarr container and the mesh-sonarr-downloads step container go with the Dockerfile, build bases and bus credential. The step runs node on the bundle with its words in the process's env, the bound clients' files, the app's config.xml and its memory read where the mesh writes them; it still runs again when a binding it reads changes.
The mesh-qbittorrent container goes with its Dockerfile, build bases and bus credential; its env becomes the bundle's words with mount targets folded back to host paths.
The mesh-nzbget container goes with its Dockerfile, build bases and bus credential; its env becomes the bundle's words with mount targets folded back to host paths.
The mesh-kometa container goes with its Dockerfile, build bases and bus credential; its env becomes the bundle's words with mount targets folded back to host paths.
The mesh-jackett container goes with its Dockerfile, build bases and bus credential; its env becomes the bundle's words with mount targets folded back to host paths.
The mesh-plex container goes with its Dockerfile, build bases, bus credential and state directory. The token is still read from the server's own Preferences.xml, now under the config directory where the mesh places it: the code looked for it beneath a data directory that was only the container's layout, and a manifest cannot name a placed directory's parent, so the client takes the config directory itself (MESH_PLEX_CONFIG_DIR), keeping the old word for a hand run.
The step already left a found feed as found when the app refused to save it. An app can also save
it and then fail its own test — saving validates settings, the test runs a live search — and that
shape failed the whole apply. One dead public tracker stopped the home server converging for six
hours, and a clean apply gates the found firewall's retirement, so a tracker was holding a firewall
record hostage. What decides is whose entry it is: one the mesh only found is a notice, one the
operator listed is still a failure. All four copies of the step, and a test with the machine's own
message that models the app's two validations apart.
The mesh's filter is composed from every module's listens, why text included,
and the renderer fills every ${port:N} it finds in a written file — refusing
one the writing module did not declare. Two why texts quoted the env lines
WEBUI_PORT=${port:8112} and TORRENTING_PORT=${port:6881} literally, so the
filter file on a converging node named qbittorrent's ports as nftables' own:
"nftables has a file that says ${port:6881}, and nftables does not say it
listens on 6881" (ace, 2026-10-01). Said in words instead.
The step adopts the jackett feeds it finds in radarr/sonarr/lidarr/bookshelf
and re-points them at the mesh's jackett. Two of radarr's (KAT, Torlock) are
dead at the source, radarr refuses to save them, and the step exited 1 on
every apply — the node reported wrong, each heartbeat, about a public tracker
nothing in the mesh can repair. Such an entry is now a notice ("left as
found", with radarr's words and the two remedies); an indexer the settings
list is still a failure, as the mesh was told to make it.
The library search returned title, year, status and monitored. It now
returns every field the app keeps (file on disk, quality, size, path,
counts, ratings, genres, added…), and each module binds plex-api so the
first ten hits carry Plex's view: rating key, library, resolution, added,
watched, and a link that opens the item in Plex.
Sonarr's first root folder is /anime, so an unnamed add landed a series
there. A profile is a preference and the first stands in; a root folder
decides where data lands, so with several it is named or the refusal
lists them. Lidarr's lookup used title where the field is artistName.
Each gains _lookup (the metadata source, by title or by id), _add (by TMDb,
TVDb or MusicBrainz id, with the first quality/metadata profile and root
folder unless named, monitored, searching only when asked) and _remove (by
the app's id, files kept unless asked).
The keys carry backslashes (WebUI\Username); awk -v escape-processes them,
so the edit matched nothing and the vault's credential never reached the
software. Python edits the file literally and also sets BanDuration=60.
The jackett, sonarr, radarr and lidarr runtimes discovered the key from
the software's config at start, so after a rotation they held the old one.
They now read the vault's file first and restart when it is remade.
qBittorrent's init sets WebUI\BanDuration=60 so a consumer's step still
carrying the previous value no longer locks the others out for an hour.
nzbget, qbittorrent, jackett, sonarr, radarr and lidarr each hold one
credential; the offer now names the provider's own secret as the
provision's credential, that secret is taken at start, and a
custom-cont-init script applies the file to the software on every start
(nzbget: NZBGET_USER beside the password it already took as a start
option; qbittorrent: the WebUI login's PBKDF2 hash; jackett: APIKey in
ServerConfig.json; the arrs: <ApiKey> in config.xml). Nothing is accepted
per consumer any more; rotating the provider's secret reaches everyone.
The runtime config carries `username` (the manifest's default, the
assignment's value); the clients looked for `user`, fell through to the
software's config file — empty at the sidecar's start on a fresh
placement — and defaulted to the software's own login. On ace the tools
answered 401 while the server itself accepted the same credentials.
PUID/PGID (PLEX_UID/PLEX_GID for plex) were 1000:1000 in every definition —
one machine's fact written where it is true of no other (ADR 0112). Each
module now renders identity.env from ${setting:puid} and ${setting:pgid};
the mesh-wide layer carries the image's default, a node whose data belongs
to somebody else says so. An adopted machine's library must never be
re-owned (ace: 1001:2000, hq 153).
Twelve definitions stop naming /var/lib/mesh/<module>: the directory says `place: "mesh"` (kometa
gains the directory it never declared), and every credential and mount names it as
${dir:mesh-state}. Every access has an id, kept beside its path as the default an assignment may
replace, and the host side of every mount says ${access:<id>} — so a home server's assignment can
say `accesses: {series: "/storage/media/series", …}` and `places: {config: {path: …, owner: …}}`
and the mounts follow. Resolved with no placement, eleven converted definitions name exactly the
paths they named before (TestPlacedDirectoriesKeepTheirPaths over both checkouts); kometa's added
directory is where the mesh already writes.
Needs the controller from mesh-controller #175/#176, running since 2026-10-01 00:06.
sonarr, radarr, lidarr, bazarr, nzbget, qbittorrent, jackett, bookshelf,
plex, tautulli, kometa and ombi, taken from the novox/mesh-catalog branches
that prepared them for ace (PRs 145-168), consolidated in stack order.
kometa gains a minimal runtime sidecar (kometa_status, kometa_config) and
declares its tmdb key as an own secret instead of a "secret" requirement.