After their code moved out of the module containers (#13), bazarr's and tautulli's bundles failed to load on the live machine: "no API key". The bundles now run as the node runtime's account. The app's config directory belongs to the account the app runs as there, set per machine through puid/pgid, with mode 0700. The runtime cannot read it.
Both now read the file directly when they may. Otherwise they read it through the app's own container (docker exec <container> cat), which owns the file. The bundle and the step get MESH_BAZARR_CONTAINER or MESH_TAUTULLI_CONTAINER. Without that variable, behaviour is unchanged.
Checked: both typecheck, and their tests pass, 8 and 11. On the live machine, the runtime's account can read both files through the containers.
After their code moved out of the module containers (#13), bazarr's and tautulli's bundles failed to load on the live machine: "no API key". The bundles now run as the node runtime's account. The app's config directory belongs to the account the app runs as there, set per machine through puid/pgid, with mode 0700. The runtime cannot read it.
Both now read the file directly when they may. Otherwise they read it through the app's own container (`docker exec <container> cat`), which owns the file. The bundle and the step get `MESH_BAZARR_CONTAINER` or `MESH_TAUTULLI_CONTAINER`. Without that variable, behaviour is unchanged.
Checked: both typecheck, and their tests pass, 8 and 11. On the live machine, the runtime's account can read both files through the containers.
Moved out of their containers, their code runs as the node runtime's account, which may not read
the app's config directory: it belongs to the account the app runs as on that machine, mode 0700.
Read the file directly when allowed, else through the app's own container, which owns it.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
After their code moved out of the module containers (#13), bazarr's and tautulli's bundles failed to load on the live machine: "no API key". The bundles now run as the node runtime's account. The app's config directory belongs to the account the app runs as there, set per machine through puid/pgid, with mode 0700. The runtime cannot read it.
Both now read the file directly when they may. Otherwise they read it through the app's own container (
docker exec <container> cat), which owns the file. The bundle and the step getMESH_BAZARR_CONTAINERorMESH_TAUTULLI_CONTAINER. Without that variable, behaviour is unchanged.Checked: both typecheck, and their tests pass, 8 and 11. On the live machine, the runtime's account can read both files through the containers.