The jackett, sonarr, radarr and lidarr runtimes discovered the key from the software's config at start, so after a rotation they held the old one. They now read the vault's file first and restart when it is remade. qBittorrent's init sets WebUI\BanDuration=60 so a consumer's step still carrying the previous value no longer locks the others out for an hour.
197 lines
6.2 KiB
JSON
197 lines
6.2 KiB
JSON
{
|
|
"module": "qbittorrent",
|
|
"version": "1",
|
|
"slug": "qbt",
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"emits": [
|
|
"download.added",
|
|
"download.completed"
|
|
],
|
|
"consumes": [],
|
|
"own-secrets": {
|
|
"broker": "${dir:mesh-state}/broker",
|
|
"password": {
|
|
"path": "${dir:mesh-state}/password",
|
|
"taken": "at-start"
|
|
}
|
|
},
|
|
"listens": [
|
|
{
|
|
"name": "web",
|
|
"port": 8112,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the download client's pages, and the WebUI API its consumers and its own tools call. qBittorrent refuses a request whose Host names a port other than the one it listens on, so it listens on the machine port itself (host network, WEBUI_PORT=${port:8112}) and the two cannot differ on any machine"
|
|
},
|
|
{
|
|
"name": "peers",
|
|
"port": 6881,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "incoming BitTorrent peer connections; announced to trackers and peers, so qBittorrent listens on the machine port itself (TORRENTING_PORT=${port:6881})"
|
|
},
|
|
{
|
|
"name": "peers-udp",
|
|
"port": 6881,
|
|
"protocol": "udp",
|
|
"from": "mesh",
|
|
"why": "DHT and uTP on the same number as the peer port"
|
|
}
|
|
],
|
|
"accesses": [
|
|
{
|
|
"id": "downloads",
|
|
"path": "/services/media/downloads",
|
|
"mode": "read-write"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "mesh"
|
|
},
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "."
|
|
},
|
|
{
|
|
"id": "config",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"owner": "1000:1000"
|
|
},
|
|
{
|
|
"id": "identity",
|
|
"type": "file",
|
|
"path": "${dir:state}/identity.env",
|
|
"mode": "0644",
|
|
"content": "# The identity this module's process runs as on THIS machine: the owner of its\n# data here, which the definition may not know (novox/hq ADR 0112, issue 153). Set puid and\n# pgid on the assignment \u2014 the mesh-wide layer carries the image's default, a node's its own.\nPUID=${setting:puid}\nPGID=${setting:pgid}\n"
|
|
},
|
|
{
|
|
"id": "mesh-init",
|
|
"type": "directory",
|
|
"mode": "0755"
|
|
},
|
|
{
|
|
"id": "webui-login-init",
|
|
"type": "file",
|
|
"path": "${dir:mesh-init}/10-mesh-webui-login.sh",
|
|
"mode": "0755",
|
|
"content": "#!/bin/bash\n# Written by the mesh (ADR 0158): this module's one credential is the vault's, shared with every\n# consumer; the file is applied here, before the service starts, on every start.\nset -euo pipefail\nCONF=/config/qBittorrent/qBittorrent.conf\nUSER='${setting:username}'\nPASS=$(cat /run/secrets/password)\nmkdir -p /config/qBittorrent\nHASH=$(python3 - \"$PASS\" <<'PY'\nimport sys, os, base64, hashlib\npw = sys.argv[1].encode(); salt = os.urandom(16)\ndk = hashlib.pbkdf2_hmac(\"sha512\", pw, salt, 100000, dklen=64)\nprint(\"@ByteArray(\" + base64.b64encode(salt).decode() + \":\" + base64.b64encode(dk).decode() + \")\")\nPY\n)\ntouch \"$CONF\"\ngrep -q '^\\[Preferences\\]' \"$CONF\" || printf '\\n[Preferences]\\n' >> \"$CONF\"\nfor kv in \"WebUI\\\\Username=$USER\" \"WebUI\\\\Password_PBKDF2=\\\"$HASH\\\"\" \"WebUI\\\\BanDuration=60\"; do\n key=${kv%%=*}\n if grep -q \"^${key//\\\\/\\\\\\\\}=\" \"$CONF\"; then\n awk -v kv=\"$kv\" -v key=\"$key\" 'BEGIN{FS=OFS=\"=\"} $1==key {print kv; next} {print}' \"$CONF\" > \"$CONF.mesh\" && mv \"$CONF.mesh\" \"$CONF\"\n else\n awk -v kv=\"$kv\" '{print} /^\\[Preferences\\]/ && !done {print kv; done=1}' \"$CONF\" > \"$CONF.mesh\" && mv \"$CONF.mesh\" \"$CONF\"\n fi\ndone\necho \"[mesh] qBittorrent WebUI login set for $USER from the vault's credential\"\n"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "qbittorrent",
|
|
"image": "lscr.io/linuxserver/qbittorrent@sha256:457e4eec2ee3f5e4ef59f237ad51f6143deba9f7445ab48bb5204a98888ef9aa",
|
|
"env": {
|
|
"TZ": "Etc/UTC",
|
|
"WEBUI_PORT": "${port:8112}",
|
|
"TORRENTING_PORT": "${port:6881}"
|
|
},
|
|
"volumes": [
|
|
"${dir:config}:/config",
|
|
"${access:downloads}:/downloads",
|
|
"${dir:mesh-init}:/custom-cont-init.d:ro",
|
|
"${dir:mesh-state}/password:/run/secrets/password:ro"
|
|
],
|
|
"network": "host",
|
|
"env-file": [
|
|
"${dir:state}/identity.env"
|
|
],
|
|
"restart-on": [
|
|
"identity",
|
|
"needs-password",
|
|
"webui-login-init"
|
|
]
|
|
},
|
|
{
|
|
"id": "runtime-config",
|
|
"type": "file",
|
|
"path": "${dir:state}/config.json",
|
|
"mode": "0600",
|
|
"content": "{}\n",
|
|
"merge": "json"
|
|
},
|
|
{
|
|
"id": "runtime",
|
|
"type": "container",
|
|
"name": "mesh-qbittorrent",
|
|
"network": "host",
|
|
"volumes": [
|
|
"${dir:mesh-state}/broker:/run/secrets/broker:ro",
|
|
"${dir:mesh-state}/password:/run/secrets/password:ro",
|
|
"${dir:state}/config.json:/run/config/config.json:ro",
|
|
"${dir:config}:/var/lib/qbittorrent/config:ro"
|
|
],
|
|
"env": {
|
|
"MESH_BROKER_FILE": "/run/secrets/broker",
|
|
"MESH_QBITTORRENT_URL": "http://127.0.0.1:${port:8112}",
|
|
"MESH_QBITTORRENT_PASSWORD_FILE": "/run/secrets/password",
|
|
"MESH_QBITTORRENT_CONFIG_FILE": "/run/config/config.json",
|
|
"MESH_QBITTORRENT_CONFIG_DIR": "/var/lib/qbittorrent/config"
|
|
},
|
|
"restart-on": [
|
|
"runtime-config",
|
|
"needs-password"
|
|
],
|
|
"artifact": "runtime"
|
|
}
|
|
],
|
|
"provides": [
|
|
{
|
|
"name": "qbittorrent-api",
|
|
"credential": {
|
|
"own": "password"
|
|
}
|
|
}
|
|
],
|
|
"serves": {
|
|
"qbittorrent-api": {
|
|
"scheme": "http",
|
|
"port": 8112,
|
|
"url-base": "",
|
|
"username": "admin"
|
|
}
|
|
},
|
|
"requires": [
|
|
"route"
|
|
],
|
|
"contributes": {
|
|
"route": {
|
|
"label": "qbittorrent",
|
|
"endpoint": "web"
|
|
}
|
|
},
|
|
"binds": {
|
|
"route": "${dir:state}/route.json"
|
|
},
|
|
"build": {
|
|
"on": [
|
|
{
|
|
"arg": "BUILD_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "build"
|
|
},
|
|
{
|
|
"arg": "RUNTIME_BASE",
|
|
"module": "mesh-tools",
|
|
"artifact": "runtime"
|
|
}
|
|
],
|
|
"artifacts": [
|
|
{
|
|
"name": "runtime",
|
|
"kind": "image",
|
|
"from": "Dockerfile"
|
|
}
|
|
]
|
|
}
|
|
}
|