The mesh-tautulli container and the mesh-tautulli-plex step container go with the Dockerfile, build bases and bus credential. The step runs node on the bundle and reads the plex binding where the mesh writes it; it still runs again when the server or the binding changes.
PUID/PGID (PLEX_UID/PLEX_GID for plex) were 1000:1000 in every definition —
one machine's fact written where it is true of no other (ADR 0112). Each
module now renders identity.env from ${setting:puid} and ${setting:pgid};
the mesh-wide layer carries the image's default, a node whose data belongs
to somebody else says so. An adopted machine's library must never be
re-owned (ace: 1001:2000, hq 153).
Twelve definitions stop naming /var/lib/mesh/<module>: the directory says `place: "mesh"` (kometa
gains the directory it never declared), and every credential and mount names it as
${dir:mesh-state}. Every access has an id, kept beside its path as the default an assignment may
replace, and the host side of every mount says ${access:<id>} — so a home server's assignment can
say `accesses: {series: "/storage/media/series", …}` and `places: {config: {path: …, owner: …}}`
and the mounts follow. Resolved with no placement, eleven converted definitions name exactly the
paths they named before (TestPlacedDirectoriesKeepTheirPaths over both checkouts); kometa's added
directory is where the mesh already writes.
Needs the controller from mesh-controller #175/#176, running since 2026-10-01 00:06.
sonarr, radarr, lidarr, bazarr, nzbget, qbittorrent, jackett, bookshelf,
plex, tautulli, kometa and ombi, taken from the novox/mesh-catalog branches
that prepared them for ace (PRs 145-168), consolidated in stack order.
kometa gains a minimal runtime sidecar (kometa_status, kometa_config) and
declares its tmdb key as an own secret instead of a "secret" requirement.