Files
mesh-media-catalog/modules/qbittorrent/module.json
T
jschoubben 8143811c84 Sidecars read the vault's key and restart when it is remade; a stale WebUI attempt bans for a minute
The jackett, sonarr, radarr and lidarr runtimes discovered the key from
the software's config at start, so after a rotation they held the old one.
They now read the vault's file first and restart when it is remade.
qBittorrent's init sets WebUI\BanDuration=60 so a consumer's step still
carrying the previous value no longer locks the others out for an hour.
2026-10-01 13:35:45 +02:00

197 lines
6.2 KiB
JSON

{
"module": "qbittorrent",
"version": "1",
"slug": "qbt",
"capabilities": [
"container-runtime"
],
"emits": [
"download.added",
"download.completed"
],
"consumes": [],
"own-secrets": {
"broker": "${dir:mesh-state}/broker",
"password": {
"path": "${dir:mesh-state}/password",
"taken": "at-start"
}
},
"listens": [
{
"name": "web",
"port": 8112,
"protocol": "tcp",
"from": "mesh",
"why": "the download client's pages, and the WebUI API its consumers and its own tools call. qBittorrent refuses a request whose Host names a port other than the one it listens on, so it listens on the machine port itself (host network, WEBUI_PORT=${port:8112}) and the two cannot differ on any machine"
},
{
"name": "peers",
"port": 6881,
"protocol": "tcp",
"from": "mesh",
"why": "incoming BitTorrent peer connections; announced to trackers and peers, so qBittorrent listens on the machine port itself (TORRENTING_PORT=${port:6881})"
},
{
"name": "peers-udp",
"port": 6881,
"protocol": "udp",
"from": "mesh",
"why": "DHT and uTP on the same number as the peer port"
}
],
"accesses": [
{
"id": "downloads",
"path": "/services/media/downloads",
"mode": "read-write"
}
],
"resources": [
{
"id": "mesh-state",
"type": "directory",
"mode": "0700",
"place": "mesh"
},
{
"id": "state",
"type": "directory",
"mode": "0700",
"place": "."
},
{
"id": "config",
"type": "directory",
"mode": "0700",
"owner": "1000:1000"
},
{
"id": "identity",
"type": "file",
"path": "${dir:state}/identity.env",
"mode": "0644",
"content": "# The identity this module's process runs as on THIS machine: the owner of its\n# data here, which the definition may not know (novox/hq ADR 0112, issue 153). Set puid and\n# pgid on the assignment \u2014 the mesh-wide layer carries the image's default, a node's its own.\nPUID=${setting:puid}\nPGID=${setting:pgid}\n"
},
{
"id": "mesh-init",
"type": "directory",
"mode": "0755"
},
{
"id": "webui-login-init",
"type": "file",
"path": "${dir:mesh-init}/10-mesh-webui-login.sh",
"mode": "0755",
"content": "#!/bin/bash\n# Written by the mesh (ADR 0158): this module's one credential is the vault's, shared with every\n# consumer; the file is applied here, before the service starts, on every start.\nset -euo pipefail\nCONF=/config/qBittorrent/qBittorrent.conf\nUSER='${setting:username}'\nPASS=$(cat /run/secrets/password)\nmkdir -p /config/qBittorrent\nHASH=$(python3 - \"$PASS\" <<'PY'\nimport sys, os, base64, hashlib\npw = sys.argv[1].encode(); salt = os.urandom(16)\ndk = hashlib.pbkdf2_hmac(\"sha512\", pw, salt, 100000, dklen=64)\nprint(\"@ByteArray(\" + base64.b64encode(salt).decode() + \":\" + base64.b64encode(dk).decode() + \")\")\nPY\n)\ntouch \"$CONF\"\ngrep -q '^\\[Preferences\\]' \"$CONF\" || printf '\\n[Preferences]\\n' >> \"$CONF\"\nfor kv in \"WebUI\\\\Username=$USER\" \"WebUI\\\\Password_PBKDF2=\\\"$HASH\\\"\" \"WebUI\\\\BanDuration=60\"; do\n key=${kv%%=*}\n if grep -q \"^${key//\\\\/\\\\\\\\}=\" \"$CONF\"; then\n awk -v kv=\"$kv\" -v key=\"$key\" 'BEGIN{FS=OFS=\"=\"} $1==key {print kv; next} {print}' \"$CONF\" > \"$CONF.mesh\" && mv \"$CONF.mesh\" \"$CONF\"\n else\n awk -v kv=\"$kv\" '{print} /^\\[Preferences\\]/ && !done {print kv; done=1}' \"$CONF\" > \"$CONF.mesh\" && mv \"$CONF.mesh\" \"$CONF\"\n fi\ndone\necho \"[mesh] qBittorrent WebUI login set for $USER from the vault's credential\"\n"
},
{
"id": "server",
"type": "container",
"name": "qbittorrent",
"image": "lscr.io/linuxserver/qbittorrent@sha256:457e4eec2ee3f5e4ef59f237ad51f6143deba9f7445ab48bb5204a98888ef9aa",
"env": {
"TZ": "Etc/UTC",
"WEBUI_PORT": "${port:8112}",
"TORRENTING_PORT": "${port:6881}"
},
"volumes": [
"${dir:config}:/config",
"${access:downloads}:/downloads",
"${dir:mesh-init}:/custom-cont-init.d:ro",
"${dir:mesh-state}/password:/run/secrets/password:ro"
],
"network": "host",
"env-file": [
"${dir:state}/identity.env"
],
"restart-on": [
"identity",
"needs-password",
"webui-login-init"
]
},
{
"id": "runtime-config",
"type": "file",
"path": "${dir:state}/config.json",
"mode": "0600",
"content": "{}\n",
"merge": "json"
},
{
"id": "runtime",
"type": "container",
"name": "mesh-qbittorrent",
"network": "host",
"volumes": [
"${dir:mesh-state}/broker:/run/secrets/broker:ro",
"${dir:mesh-state}/password:/run/secrets/password:ro",
"${dir:state}/config.json:/run/config/config.json:ro",
"${dir:config}:/var/lib/qbittorrent/config:ro"
],
"env": {
"MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_QBITTORRENT_URL": "http://127.0.0.1:${port:8112}",
"MESH_QBITTORRENT_PASSWORD_FILE": "/run/secrets/password",
"MESH_QBITTORRENT_CONFIG_FILE": "/run/config/config.json",
"MESH_QBITTORRENT_CONFIG_DIR": "/var/lib/qbittorrent/config"
},
"restart-on": [
"runtime-config",
"needs-password"
],
"artifact": "runtime"
}
],
"provides": [
{
"name": "qbittorrent-api",
"credential": {
"own": "password"
}
}
],
"serves": {
"qbittorrent-api": {
"scheme": "http",
"port": 8112,
"url-base": "",
"username": "admin"
}
},
"requires": [
"route"
],
"contributes": {
"route": {
"label": "qbittorrent",
"endpoint": "web"
}
},
"binds": {
"route": "${dir:state}/route.json"
},
"build": {
"on": [
{
"arg": "BUILD_BASE",
"module": "mesh-tools",
"artifact": "build"
},
{
"arg": "RUNTIME_BASE",
"module": "mesh-tools",
"artifact": "runtime"
}
],
"artifacts": [
{
"name": "runtime",
"kind": "image",
"from": "Dockerfile"
}
]
}
}