Moved out of their containers, their code runs as the node runtime's account, which may not read the app's config directory: it belongs to the account the app runs as on that machine, mode 0700. Read the file directly when allowed, else through the app's own container, which owns it.
mesh-media-catalog
The media chain as Novox Mesh modules, one per directory under modules/: the
servarr trio (sonarr, radarr, lidarr), bazarr, the downloaders (nzbget, qbittorrent), jackett,
bookshelf, plex and its companions (tautulli, kometa), and ombi.
It is a catalogue in the exact shape of novox/mesh-catalog:
the same manifest vocabulary, the same rules, checked the same way. It is separate because this
chain is one system that only talks to itself — jackett-api, sonarr-api, radarr-api, lidarr-api
and plex-api are exchanged among these modules and consumed by nothing else except
home-assistant — and because what runs here is one operator's media stack, pinned to the builds
in use, not shared infrastructure. Provisions cross repositories freely: lidarr requires
postgres-database from the catalogue's postgres, every module requires route; the mesh
resolves a requirement by name and never by where the manifest lives.
Conventions
- A manifest names the software's own ports and nothing of the machine: machine ports are
assigned by the mesh, per node. No
host:containerpairs, no pins in an assignment. - A manifest names no installation: no hostnames, paths of a particular machine, or people.
Names come from
${bound:route:name}, places from${dir:<id>}, values from settings. - Every secret a module needs is declared under
own-secrets(minted, or accepted once for an adopted instance); a provision's credential arrives with its binding. - Each module carries a small runtime sidecar (
tools/index.ts, built by itsDockerfileon the mesh-tools bases) with a few query tools — the working example to extend.
Before pushing, check every manifest together, the way registration does:
mesh-controller module check modules/*/module.json
Register a module from this repository through the forge seat:
module add /<m>.json --source novox/mesh-media-catalog --self --path modules/<m> --ref main --commit <sha>
build novox/mesh-media-catalog --self --path modules/<m> --ref main