The mesh-qbittorrent container goes with its Dockerfile, build bases and bus credential; its env becomes the bundle's words with mount targets folded back to host paths.
174 lines
5.8 KiB
JSON
174 lines
5.8 KiB
JSON
{
|
|
"module": "qbittorrent",
|
|
"version": "1",
|
|
"slug": "qbt",
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"emits": [
|
|
"download.added",
|
|
"download.completed"
|
|
],
|
|
"consumes": [],
|
|
"own-secrets": {
|
|
"password": {
|
|
"path": "${dir:mesh-state}/password",
|
|
"taken": "at-start"
|
|
}
|
|
},
|
|
"listens": [
|
|
{
|
|
"name": "web",
|
|
"port": 8112,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "the download client's pages, and the WebUI API its consumers and its own tools call. qBittorrent refuses a request whose Host names a port other than the one it listens on, so it listens on the machine port itself (host network, WEBUI_PORT is the machine port) and the two cannot differ on any machine"
|
|
},
|
|
{
|
|
"name": "peers",
|
|
"port": 6881,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "incoming BitTorrent peer connections; announced to trackers and peers, so qBittorrent listens on the machine port itself (TORRENTING_PORT is the machine port)"
|
|
},
|
|
{
|
|
"name": "peers-udp",
|
|
"port": 6881,
|
|
"protocol": "udp",
|
|
"from": "mesh",
|
|
"why": "DHT and uTP on the same number as the peer port"
|
|
}
|
|
],
|
|
"accesses": [
|
|
{
|
|
"id": "downloads",
|
|
"path": "/services/media/downloads",
|
|
"mode": "read-write"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "mesh"
|
|
},
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "."
|
|
},
|
|
{
|
|
"id": "config",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"owner": "1000:1000"
|
|
},
|
|
{
|
|
"id": "identity",
|
|
"type": "file",
|
|
"path": "${dir:state}/identity.env",
|
|
"mode": "0644",
|
|
"content": "# The identity this module's process runs as on THIS machine: the owner of its\n# data here, which the definition may not know (novox/hq ADR 0112, issue 153). Set puid and\n# pgid on the assignment — the mesh-wide layer carries the image's default, a node's its own.\nPUID=${setting:puid}\nPGID=${setting:pgid}\n"
|
|
},
|
|
{
|
|
"id": "mesh-init",
|
|
"type": "directory",
|
|
"mode": "0755"
|
|
},
|
|
{
|
|
"id": "webui-login-init",
|
|
"type": "file",
|
|
"path": "${dir:mesh-init}/10-mesh-webui-login.sh",
|
|
"mode": "0755",
|
|
"content": "#!/bin/bash\n# Written by the mesh (ADR 0158): this module's one credential is the vault's, shared with every\n# consumer; the WebUI login is written into qBittorrent.conf here, before the service starts, on\n# every start. Keys carry backslashes, so the edit is python's, not awk's.\nset -euo pipefail\nmkdir -p /config/qBittorrent\nUSERNAME='${setting:username}' python3 - <<'PY'\nimport os, re, base64, hashlib\nconf = \"/config/qBittorrent/qBittorrent.conf\"\npw = open(\"/run/secrets/password\", \"rb\").read().strip()\nsalt = os.urandom(16)\ndk = hashlib.pbkdf2_hmac(\"sha512\", pw, salt, 100000, dklen=64)\nhash_ = \"@ByteArray(\" + base64.b64encode(salt).decode() + \":\" + base64.b64encode(dk).decode() + \")\"\nwant = {\n \"WebUI\\\\Username\": os.environ[\"USERNAME\"],\n \"WebUI\\\\Password_PBKDF2\": '\"' + hash_ + '\"',\n \"WebUI\\\\BanDuration\": \"60\",\n}\ntext = open(conf).read() if os.path.exists(conf) else \"\"\nlines = text.splitlines()\nif \"[Preferences]\" not in lines:\n lines += [\"\", \"[Preferences]\"]\nout, seen = [], set()\nfor line in lines:\n key = line.split(\"=\", 1)[0] if \"=\" in line else None\n if key in want:\n out.append(key + \"=\" + want[key]); seen.add(key)\n else:\n out.append(line)\nmissing = [k for k in want if k not in seen]\nif missing:\n at = out.index(\"[Preferences]\") + 1\n out[at:at] = [k + \"=\" + want[k] for k in missing]\nopen(conf, \"w\").write(\"\\n\".join(out) + \"\\n\")\nprint(\"[mesh] qBittorrent WebUI login set for \" + os.environ[\"USERNAME\"] + \" from the vault's credential; ban duration 60s\")\nPY\n"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "qbittorrent",
|
|
"image": "lscr.io/linuxserver/qbittorrent@sha256:457e4eec2ee3f5e4ef59f237ad51f6143deba9f7445ab48bb5204a98888ef9aa",
|
|
"env": {
|
|
"TZ": "Etc/UTC",
|
|
"WEBUI_PORT": "${port:8112}",
|
|
"TORRENTING_PORT": "${port:6881}"
|
|
},
|
|
"volumes": [
|
|
"${dir:config}:/config",
|
|
"${access:downloads}:/downloads",
|
|
"${dir:mesh-init}:/custom-cont-init.d:ro",
|
|
"${dir:mesh-state}/password:/run/secrets/password:ro"
|
|
],
|
|
"network": "host",
|
|
"env-file": [
|
|
"${dir:state}/identity.env"
|
|
],
|
|
"restart-on": [
|
|
"identity",
|
|
"needs-password",
|
|
"webui-login-init"
|
|
]
|
|
},
|
|
{
|
|
"id": "runtime-config",
|
|
"type": "file",
|
|
"path": "${dir:state}/config.json",
|
|
"mode": "0600",
|
|
"content": "{}\n",
|
|
"merge": "json"
|
|
}
|
|
],
|
|
"provides": [
|
|
{
|
|
"name": "qbittorrent-api",
|
|
"credential": {
|
|
"own": "password"
|
|
}
|
|
}
|
|
],
|
|
"serves": {
|
|
"qbittorrent-api": {
|
|
"scheme": "http",
|
|
"port": 8112,
|
|
"url-base": "",
|
|
"username": "admin"
|
|
}
|
|
},
|
|
"requires": [
|
|
"route"
|
|
],
|
|
"contributes": {
|
|
"route": {
|
|
"label": "qbittorrent",
|
|
"endpoint": "web"
|
|
}
|
|
},
|
|
"binds": {
|
|
"route": "${dir:state}/route.json"
|
|
},
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "code",
|
|
"kind": "bundle",
|
|
"language": "typescript",
|
|
"entrypoints": [
|
|
"index.js",
|
|
"tools/index.js"
|
|
],
|
|
"loads": [
|
|
"index.js",
|
|
"tools/index.js"
|
|
],
|
|
"env": {
|
|
"MESH_QBITTORRENT_URL": "http://127.0.0.1:${port:8112}",
|
|
"MESH_QBITTORRENT_PASSWORD_FILE": "${dir:mesh-state}/password",
|
|
"MESH_QBITTORRENT_CONFIG_FILE": "${dir:state}/config.json",
|
|
"MESH_QBITTORRENT_CONFIG_DIR": "${dir:config}"
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|