audiobookshelf: within-major step, both venues proven (R-462, Part F)
{'audiobookshelf': 'ghcr.io/advplyr/audiobookshelf:2.36.1'} -> {'audiobookshelf': 'ghcr.io/advplyr/audiobookshelf:2.37.1'}
The ONLY image move in this commit. Written by upgrade-test.py --write-ladder (gates rc=0):
- bench LXC 9401 (harness v4): the seed read back before and after; 10-minute memory watch: audiobookshelf anon 10.5 % | migration: [2Kaudiobookshelf | [2026-09-30 13:52:16.057] INFO: [MigrationManager] No migr;
0 kills, 0 restarts; the abort starts and serves the data;
- box 9202 (controller 0.283.1, the product's guarded Update, drill catalog): done in 24.6 s, the seed
read back through the app's own front door.
Evidence: felhom.eu/documentation/audits/pg-last-six-2026-09-30/F/ and .../box/audiobookshelf/
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -10,7 +10,7 @@ subdomain: "audiobooks"
|
||||
slug: "audiobookshelf"
|
||||
# catalog_since: the date THIS repo last changed this app's pinned images. Any commit that
|
||||
# changes an image: line must set this to the same day (see CLAUDE.md).
|
||||
catalog_since: "2026-09-22"
|
||||
catalog_since: "2026-09-30"
|
||||
|
||||
# --- Resource hints (displayed on deploy screen) ---
|
||||
resources:
|
||||
@@ -137,3 +137,4 @@ i18n:
|
||||
# gated by scripts/check-test-record.py. An image: move without a proven entry here is refused.
|
||||
update_ladder:
|
||||
- {"from": {"audiobookshelf": "ghcr.io/advplyr/audiobookshelf:2.35.1"}, "to": {"audiobookshelf": "ghcr.io/advplyr/audiobookshelf:2.36.1"}, "digest": {"audiobookshelf": "sha256:3528a93b6442ffe54bd46771bbbab7c97084e1101071586d9dc2254f30bb4358"}, "verdict": "proven", "tested_at": "2026-09-21T18:44:43.824636+00:00", "harness_version": 1, "evidence": "felhom.eu/documentation/audits/update-night-2026-09-21/apps/audiobookshelf/verdict.json", "memory_peak_pct": null, "marks": {"files_may_change": false, "needs_person": null, "memory_tight": false}, "backfilled": "2026-09-23", "note": "backfilled from catalog commit 6525b8e; box walk only (harness v1, no memory watch); digest = what the registry served on 2026-09-23, not a measurement of the tested image"}
|
||||
- {"from": {"audiobookshelf": "ghcr.io/advplyr/audiobookshelf:2.36.1"}, "to": {"audiobookshelf": "ghcr.io/advplyr/audiobookshelf:2.37.1"}, "digest": {"audiobookshelf": "sha256:581d68b2a6fc7ebf58d81c878a9f387cbbc0d88ac9d37b298b9cee10168af85b"}, "verdict": "proven", "tested_at": "2026-09-30T12:03:23Z", "harness_version": 4, "evidence": "felhom.eu/documentation/audits/pg-last-six-2026-09-30/F/apps/audiobookshelf/bench/evidence/MV-audiobookshelf/verdict.json", "box_evidence": "felhom.eu/documentation/audits/pg-last-six-2026-09-30/box/audiobookshelf/box-verdict-audiobookshelf.json", "memory_peak_pct": 10.5, "marks": {"files_may_change": false, "needs_person": null, "memory_tight": false}, "memory_basis": "anon", "memory_cgroup_peak_pct": 14.0}
|
||||
|
||||
@@ -17,7 +17,7 @@
|
||||
|
||||
services:
|
||||
audiobookshelf:
|
||||
image: ghcr.io/advplyr/audiobookshelf:2.36.1
|
||||
image: ghcr.io/advplyr/audiobookshelf:2.37.1
|
||||
container_name: audiobookshelf
|
||||
restart: unless-stopped
|
||||
# Runs as root (see note above). Restore an escalation boundary: block SUID-based privilege
|
||||
|
||||
@@ -0,0 +1,133 @@
|
||||
# =============================================================================
|
||||
# .felhom.yml - App metadata for felhom-controller
|
||||
# =============================================================================
|
||||
|
||||
# --- Display info (shown on dashboard) ---
|
||||
display_name: "Audiobookshelf"
|
||||
description: "Hangoskönyv és podcast kezelő szerver"
|
||||
category: "media"
|
||||
subdomain: "audiobooks"
|
||||
slug: "audiobookshelf"
|
||||
# catalog_since: the date THIS repo last changed this app's pinned images. Any commit that
|
||||
# changes an image: line must set this to the same day (see CLAUDE.md).
|
||||
catalog_since: "2026-09-22"
|
||||
|
||||
# --- Resource hints (displayed on deploy screen) ---
|
||||
resources:
|
||||
mem_request: "100M"
|
||||
mem_limit: "512M"
|
||||
pi_compatible: true
|
||||
needs_hdd: true
|
||||
|
||||
# --- Backup classification (referential coupling; see felhom.eu documentation/audits/SPIKE-backup-classification-2026-07-14.md) ---
|
||||
backup:
|
||||
userdata:
|
||||
- path: media/audiobooks
|
||||
class: optional # PENDING-VETO: spike chose excluded; ruled optional for consistency
|
||||
# with komga/romm (curated, often personally ripped — precious).
|
||||
# If Viktor rules excluded, flip THIS LINE ONLY before committing.
|
||||
- path: media/podcasts
|
||||
class: excluded # re-downloadable by definition
|
||||
|
||||
# --- Deploy fields (first deployment only) ---
|
||||
deploy_fields:
|
||||
- env_var: DOMAIN
|
||||
label: "Domain"
|
||||
type: domain
|
||||
description: "A szerver domain neve"
|
||||
locked_after_deploy: true
|
||||
|
||||
- env_var: SUBDOMAIN
|
||||
label: "Aldomain"
|
||||
type: subdomain
|
||||
default: "audiobooks"
|
||||
required: true
|
||||
locked_after_deploy: true
|
||||
description: "Az alkalmazás aldomainje"
|
||||
|
||||
- env_var: HDD_PATH
|
||||
label: "Hangoskönyv tár útvonal"
|
||||
type: path
|
||||
required: true
|
||||
placeholder: "/mnt/felhom-drives/hdd_1"
|
||||
description: "A külső merevlemez elérési útja"
|
||||
locked_after_deploy: true
|
||||
|
||||
|
||||
# --- The setup gate (controller >= 0.280.0, `09` §3 decision 46) ---
|
||||
# The first visitor would create the admin. So a fresh install is closed to everyone but the household (a browser
|
||||
# signed in to the dashboard) until the first setup is done; audiobookshelf's own status says so (`/status` isInit — upstream, measured on 9202 by the
|
||||
# 2026-09-29 live proof).
|
||||
setup_gate: true
|
||||
# measured on 9202 2026-09-29: isInit false -> true after POST /init; the gate opened ~20 s later (audits/login-gate-2026-09-29/C).
|
||||
setup_done_probe:
|
||||
url: http://audiobookshelf:80/status
|
||||
field: isInit
|
||||
done: "true"
|
||||
|
||||
# --- App info (info page content) ---
|
||||
app_info:
|
||||
tagline: "Hangoskönyv és podcast kezelő, lejátszó és szinkronizáló"
|
||||
docs_url: "https://www.audiobookshelf.org/docs"
|
||||
|
||||
use_cases:
|
||||
- 'Hangoskönyvek és podcastok rendszerezése és lejátszása'
|
||||
- 'Automatikus metaadat letöltés - borítók, leírások, fejezetek'
|
||||
- 'Folytatás ott, ahol abbahagytad (szinkron eszközök között)'
|
||||
- 'Podcast feliratkozás és automatikus letöltés'
|
||||
- 'Dedikált mobil alkalmazások (Android, iOS)'
|
||||
|
||||
first_steps:
|
||||
- 'Nyisd meg az audiobooks.DOMAIN címet a böngészőben'
|
||||
- 'Hozd létre az admin fiókot az első megnyitáskor'
|
||||
- 'Add hozzá a könyvtárakat (/audiobooks és/vagy /podcasts)'
|
||||
- 'Várd meg az automatikus szkennelést'
|
||||
- 'Telepítsd az Audiobookshelf alkalmazást a telefonodra'
|
||||
|
||||
prerequisites:
|
||||
- 'Külső HDD szükséges a hangoskönyvek tárolásához'
|
||||
- 'Hangoskönyvek mappákba rendezve (pl. Szerző/Könyv/)'
|
||||
|
||||
# --- Controller-side health probe ---
|
||||
healthcheck:
|
||||
checks:
|
||||
- type: api
|
||||
port: 80
|
||||
path: "/healthcheck"
|
||||
expect:
|
||||
status: 200
|
||||
|
||||
# --- English copy (localisation slice 5, R-560) --------------------------------------------
|
||||
# The Hungarian above is UNCHANGED. A box on English reads this block field by field; a missing
|
||||
# field shows the Hungarian one; a controller older than 0.257.0 ignores the block entirely.
|
||||
i18n:
|
||||
en:
|
||||
description: 'An audiobook and podcast server'
|
||||
app_info:
|
||||
tagline: 'An audiobook and podcast library, player and sync'
|
||||
use_cases:
|
||||
- 'Sort and play your audiobooks and podcasts'
|
||||
- 'Details arrive on their own - covers, descriptions, chapters'
|
||||
- 'Carry on where you stopped (it syncs between devices)'
|
||||
- 'Subscribe to a podcast and let it download itself'
|
||||
- 'Apps of its own for phones (Android, iOS)'
|
||||
first_steps:
|
||||
- 'Open audiobooks.DOMAIN in your browser'
|
||||
- 'Create the admin account the first time you open it'
|
||||
- 'Add your libraries (/audiobooks and/or /podcasts)'
|
||||
- 'Wait for the first scan to finish'
|
||||
- 'Install the Audiobookshelf app on your phone'
|
||||
prerequisites:
|
||||
- 'An external hard drive is needed to keep the audiobooks on'
|
||||
- 'Audiobooks sorted into folders (Author/Book/, for example)'
|
||||
deploy_fields:
|
||||
- env_var: DOMAIN
|
||||
label: 'Domain'
|
||||
description: 'The server domain name'
|
||||
- env_var: SUBDOMAIN
|
||||
label: 'Subdomain'
|
||||
description: 'The subdomain this app answers on'
|
||||
- env_var: HDD_PATH
|
||||
label: 'Audiobook library path'
|
||||
description: 'The path to the external hard drive'
|
||||
placeholder: '/mnt/felhom-drives/hdd_1'
|
||||
@@ -0,0 +1,61 @@
|
||||
# Audiobookshelf - Hangoskönyv és podcast kezelő szerver
|
||||
# Domain: ${SUBDOMAIN}.${DOMAIN}
|
||||
# Database: None (file-based)
|
||||
# RAM: ~100M (mem_limit: 512M) | Pi-compatible: Yes
|
||||
#
|
||||
# Environment variables:
|
||||
# DOMAIN - Your domain (e.g., demo-felhom.eu)
|
||||
# USERDATA_PATH - Ügyfél-tartalom gyökér (<namespace>/userdata)
|
||||
#
|
||||
# Storage layout (felhom userdata convention):
|
||||
# Hangoskönyvek → ${USERDATA_PATH}/media/audiobooks (írható)
|
||||
# Podcastok → ${USERDATA_PATH}/media/podcasts (írható)
|
||||
# Run-identity: ROOT (fallback). user "1000:1000" was tried but the image creates its /metadata named
|
||||
# volume as root at init and fails (`EACCES mkdir /metadata/logs`) when pinned to 1000. So it runs as
|
||||
# root and relies on the setgid 2775 userdata dirs (files land group 1000 → FileBrowser can browse/read).
|
||||
# (Verified live; see REPORT.)
|
||||
|
||||
services:
|
||||
audiobookshelf:
|
||||
image: ghcr.io/advplyr/audiobookshelf:2.36.1
|
||||
container_name: audiobookshelf
|
||||
restart: unless-stopped
|
||||
# Runs as root (see note above). Restore an escalation boundary: block SUID-based privilege
|
||||
# escalation. Full cap_drop is NOT applied — the image's root-init needs file-ownership caps to
|
||||
# set up /metadata, and dropping them reproduces the EACCES failure we hit pinning user:1000.
|
||||
security_opt:
|
||||
- no-new-privileges:true
|
||||
environment:
|
||||
- TZ=Europe/Budapest
|
||||
volumes:
|
||||
- audiobookshelf_config:/config
|
||||
- audiobookshelf_metadata:/metadata
|
||||
- ${USERDATA_PATH}/media/audiobooks:/audiobooks
|
||||
- ${USERDATA_PATH}/media/podcasts:/podcasts
|
||||
networks:
|
||||
- traefik-public
|
||||
deploy:
|
||||
resources:
|
||||
limits:
|
||||
memory: 512M
|
||||
healthcheck:
|
||||
test: ["CMD", "wget", "--spider", "-q", "http://127.0.0.1:80/healthcheck"]
|
||||
interval: 30s
|
||||
timeout: 5s
|
||||
retries: 3
|
||||
start_period: 30s
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.routers.audiobookshelf.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
|
||||
- "traefik.http.routers.audiobookshelf.entrypoints=websecure"
|
||||
- "traefik.http.routers.audiobookshelf.tls=true"
|
||||
- "traefik.http.routers.audiobookshelf.tls.certresolver=letsencrypt"
|
||||
- "traefik.http.services.audiobookshelf.loadbalancer.server.port=80"
|
||||
|
||||
volumes:
|
||||
audiobookshelf_config:
|
||||
audiobookshelf_metadata:
|
||||
|
||||
networks:
|
||||
traefik-public:
|
||||
external: true
|
||||
Reference in New Issue
Block a user