Files
mesh-media-catalog/modules/qbittorrent/module.json
T
jochen 8fbed91540 qbittorrent: its watcher and tools run in the node's runtime (hq ADR 0198)
The mesh-qbittorrent container goes with its Dockerfile, build bases and bus credential; its env becomes the bundle's words with mount targets folded back to host paths.
2026-10-04 00:41:51 +02:00

174 lines
5.8 KiB
JSON

{
"module": "qbittorrent",
"version": "1",
"slug": "qbt",
"capabilities": [
"container-runtime"
],
"emits": [
"download.added",
"download.completed"
],
"consumes": [],
"own-secrets": {
"password": {
"path": "${dir:mesh-state}/password",
"taken": "at-start"
}
},
"listens": [
{
"name": "web",
"port": 8112,
"protocol": "tcp",
"from": "mesh",
"why": "the download client's pages, and the WebUI API its consumers and its own tools call. qBittorrent refuses a request whose Host names a port other than the one it listens on, so it listens on the machine port itself (host network, WEBUI_PORT is the machine port) and the two cannot differ on any machine"
},
{
"name": "peers",
"port": 6881,
"protocol": "tcp",
"from": "mesh",
"why": "incoming BitTorrent peer connections; announced to trackers and peers, so qBittorrent listens on the machine port itself (TORRENTING_PORT is the machine port)"
},
{
"name": "peers-udp",
"port": 6881,
"protocol": "udp",
"from": "mesh",
"why": "DHT and uTP on the same number as the peer port"
}
],
"accesses": [
{
"id": "downloads",
"path": "/services/media/downloads",
"mode": "read-write"
}
],
"resources": [
{
"id": "mesh-state",
"type": "directory",
"mode": "0700",
"place": "mesh"
},
{
"id": "state",
"type": "directory",
"mode": "0700",
"place": "."
},
{
"id": "config",
"type": "directory",
"mode": "0700",
"owner": "1000:1000"
},
{
"id": "identity",
"type": "file",
"path": "${dir:state}/identity.env",
"mode": "0644",
"content": "# The identity this module's process runs as on THIS machine: the owner of its\n# data here, which the definition may not know (novox/hq ADR 0112, issue 153). Set puid and\n# pgid on the assignment — the mesh-wide layer carries the image's default, a node's its own.\nPUID=${setting:puid}\nPGID=${setting:pgid}\n"
},
{
"id": "mesh-init",
"type": "directory",
"mode": "0755"
},
{
"id": "webui-login-init",
"type": "file",
"path": "${dir:mesh-init}/10-mesh-webui-login.sh",
"mode": "0755",
"content": "#!/bin/bash\n# Written by the mesh (ADR 0158): this module's one credential is the vault's, shared with every\n# consumer; the WebUI login is written into qBittorrent.conf here, before the service starts, on\n# every start. Keys carry backslashes, so the edit is python's, not awk's.\nset -euo pipefail\nmkdir -p /config/qBittorrent\nUSERNAME='${setting:username}' python3 - <<'PY'\nimport os, re, base64, hashlib\nconf = \"/config/qBittorrent/qBittorrent.conf\"\npw = open(\"/run/secrets/password\", \"rb\").read().strip()\nsalt = os.urandom(16)\ndk = hashlib.pbkdf2_hmac(\"sha512\", pw, salt, 100000, dklen=64)\nhash_ = \"@ByteArray(\" + base64.b64encode(salt).decode() + \":\" + base64.b64encode(dk).decode() + \")\"\nwant = {\n \"WebUI\\\\Username\": os.environ[\"USERNAME\"],\n \"WebUI\\\\Password_PBKDF2\": '\"' + hash_ + '\"',\n \"WebUI\\\\BanDuration\": \"60\",\n}\ntext = open(conf).read() if os.path.exists(conf) else \"\"\nlines = text.splitlines()\nif \"[Preferences]\" not in lines:\n lines += [\"\", \"[Preferences]\"]\nout, seen = [], set()\nfor line in lines:\n key = line.split(\"=\", 1)[0] if \"=\" in line else None\n if key in want:\n out.append(key + \"=\" + want[key]); seen.add(key)\n else:\n out.append(line)\nmissing = [k for k in want if k not in seen]\nif missing:\n at = out.index(\"[Preferences]\") + 1\n out[at:at] = [k + \"=\" + want[k] for k in missing]\nopen(conf, \"w\").write(\"\\n\".join(out) + \"\\n\")\nprint(\"[mesh] qBittorrent WebUI login set for \" + os.environ[\"USERNAME\"] + \" from the vault's credential; ban duration 60s\")\nPY\n"
},
{
"id": "server",
"type": "container",
"name": "qbittorrent",
"image": "lscr.io/linuxserver/qbittorrent@sha256:457e4eec2ee3f5e4ef59f237ad51f6143deba9f7445ab48bb5204a98888ef9aa",
"env": {
"TZ": "Etc/UTC",
"WEBUI_PORT": "${port:8112}",
"TORRENTING_PORT": "${port:6881}"
},
"volumes": [
"${dir:config}:/config",
"${access:downloads}:/downloads",
"${dir:mesh-init}:/custom-cont-init.d:ro",
"${dir:mesh-state}/password:/run/secrets/password:ro"
],
"network": "host",
"env-file": [
"${dir:state}/identity.env"
],
"restart-on": [
"identity",
"needs-password",
"webui-login-init"
]
},
{
"id": "runtime-config",
"type": "file",
"path": "${dir:state}/config.json",
"mode": "0600",
"content": "{}\n",
"merge": "json"
}
],
"provides": [
{
"name": "qbittorrent-api",
"credential": {
"own": "password"
}
}
],
"serves": {
"qbittorrent-api": {
"scheme": "http",
"port": 8112,
"url-base": "",
"username": "admin"
}
},
"requires": [
"route"
],
"contributes": {
"route": {
"label": "qbittorrent",
"endpoint": "web"
}
},
"binds": {
"route": "${dir:state}/route.json"
},
"build": {
"artifacts": [
{
"name": "code",
"kind": "bundle",
"language": "typescript",
"entrypoints": [
"index.js",
"tools/index.js"
],
"loads": [
"index.js",
"tools/index.js"
],
"env": {
"MESH_QBITTORRENT_URL": "http://127.0.0.1:${port:8112}",
"MESH_QBITTORRENT_PASSWORD_FILE": "${dir:mesh-state}/password",
"MESH_QBITTORRENT_CONFIG_FILE": "${dir:state}/config.json",
"MESH_QBITTORRENT_CONFIG_DIR": "${dir:config}"
}
}
]
}
}