diff --git a/templates/audiobookshelf/.felhom.yml b/templates/audiobookshelf/.felhom.yml index 4fa4ea4..67b8fc8 100644 --- a/templates/audiobookshelf/.felhom.yml +++ b/templates/audiobookshelf/.felhom.yml @@ -10,7 +10,7 @@ subdomain: "audiobooks" slug: "audiobookshelf" # catalog_since: the date THIS repo last changed this app's pinned images. Any commit that # changes an image: line must set this to the same day (see CLAUDE.md). -catalog_since: "2026-09-22" +catalog_since: "2026-09-30" # --- Resource hints (displayed on deploy screen) --- resources: @@ -137,3 +137,4 @@ i18n: # gated by scripts/check-test-record.py. An image: move without a proven entry here is refused. update_ladder: - {"from": {"audiobookshelf": "ghcr.io/advplyr/audiobookshelf:2.35.1"}, "to": {"audiobookshelf": "ghcr.io/advplyr/audiobookshelf:2.36.1"}, "digest": {"audiobookshelf": "sha256:3528a93b6442ffe54bd46771bbbab7c97084e1101071586d9dc2254f30bb4358"}, "verdict": "proven", "tested_at": "2026-09-21T18:44:43.824636+00:00", "harness_version": 1, "evidence": "felhom.eu/documentation/audits/update-night-2026-09-21/apps/audiobookshelf/verdict.json", "memory_peak_pct": null, "marks": {"files_may_change": false, "needs_person": null, "memory_tight": false}, "backfilled": "2026-09-23", "note": "backfilled from catalog commit 6525b8e; box walk only (harness v1, no memory watch); digest = what the registry served on 2026-09-23, not a measurement of the tested image"} + - {"from": {"audiobookshelf": "ghcr.io/advplyr/audiobookshelf:2.36.1"}, "to": {"audiobookshelf": "ghcr.io/advplyr/audiobookshelf:2.37.1"}, "digest": {"audiobookshelf": "sha256:581d68b2a6fc7ebf58d81c878a9f387cbbc0d88ac9d37b298b9cee10168af85b"}, "verdict": "proven", "tested_at": "2026-09-30T12:03:23Z", "harness_version": 4, "evidence": "felhom.eu/documentation/audits/pg-last-six-2026-09-30/F/apps/audiobookshelf/bench/evidence/MV-audiobookshelf/verdict.json", "box_evidence": "felhom.eu/documentation/audits/pg-last-six-2026-09-30/box/audiobookshelf/box-verdict-audiobookshelf.json", "memory_peak_pct": 10.5, "marks": {"files_may_change": false, "needs_person": null, "memory_tight": false}, "memory_basis": "anon", "memory_cgroup_peak_pct": 14.0} diff --git a/templates/audiobookshelf/docker-compose.yml b/templates/audiobookshelf/docker-compose.yml index a41a7b1..e817654 100644 --- a/templates/audiobookshelf/docker-compose.yml +++ b/templates/audiobookshelf/docker-compose.yml @@ -17,7 +17,7 @@ services: audiobookshelf: - image: ghcr.io/advplyr/audiobookshelf:2.36.1 + image: ghcr.io/advplyr/audiobookshelf:2.37.1 container_name: audiobookshelf restart: unless-stopped # Runs as root (see note above). Restore an escalation boundary: block SUID-based privilege diff --git a/templates/audiobookshelf/steps/8db6e47fe3ce3a65.felhom.yml b/templates/audiobookshelf/steps/8db6e47fe3ce3a65.felhom.yml new file mode 100644 index 0000000..e884a06 --- /dev/null +++ b/templates/audiobookshelf/steps/8db6e47fe3ce3a65.felhom.yml @@ -0,0 +1,133 @@ +# ============================================================================= +# .felhom.yml - App metadata for felhom-controller +# ============================================================================= + +# --- Display info (shown on dashboard) --- +display_name: "Audiobookshelf" +description: "Hangoskönyv és podcast kezelő szerver" +category: "media" +subdomain: "audiobooks" +slug: "audiobookshelf" +# catalog_since: the date THIS repo last changed this app's pinned images. Any commit that +# changes an image: line must set this to the same day (see CLAUDE.md). +catalog_since: "2026-09-22" + +# --- Resource hints (displayed on deploy screen) --- +resources: + mem_request: "100M" + mem_limit: "512M" + pi_compatible: true + needs_hdd: true + +# --- Backup classification (referential coupling; see felhom.eu documentation/audits/SPIKE-backup-classification-2026-07-14.md) --- +backup: + userdata: + - path: media/audiobooks + class: optional # PENDING-VETO: spike chose excluded; ruled optional for consistency + # with komga/romm (curated, often personally ripped — precious). + # If Viktor rules excluded, flip THIS LINE ONLY before committing. + - path: media/podcasts + class: excluded # re-downloadable by definition + +# --- Deploy fields (first deployment only) --- +deploy_fields: + - env_var: DOMAIN + label: "Domain" + type: domain + description: "A szerver domain neve" + locked_after_deploy: true + + - env_var: SUBDOMAIN + label: "Aldomain" + type: subdomain + default: "audiobooks" + required: true + locked_after_deploy: true + description: "Az alkalmazás aldomainje" + + - env_var: HDD_PATH + label: "Hangoskönyv tár útvonal" + type: path + required: true + placeholder: "/mnt/felhom-drives/hdd_1" + description: "A külső merevlemez elérési útja" + locked_after_deploy: true + + +# --- The setup gate (controller >= 0.280.0, `09` §3 decision 46) --- +# The first visitor would create the admin. So a fresh install is closed to everyone but the household (a browser +# signed in to the dashboard) until the first setup is done; audiobookshelf's own status says so (`/status` isInit — upstream, measured on 9202 by the +# 2026-09-29 live proof). +setup_gate: true +# measured on 9202 2026-09-29: isInit false -> true after POST /init; the gate opened ~20 s later (audits/login-gate-2026-09-29/C). +setup_done_probe: + url: http://audiobookshelf:80/status + field: isInit + done: "true" + +# --- App info (info page content) --- +app_info: + tagline: "Hangoskönyv és podcast kezelő, lejátszó és szinkronizáló" + docs_url: "https://www.audiobookshelf.org/docs" + + use_cases: + - 'Hangoskönyvek és podcastok rendszerezése és lejátszása' + - 'Automatikus metaadat letöltés - borítók, leírások, fejezetek' + - 'Folytatás ott, ahol abbahagytad (szinkron eszközök között)' + - 'Podcast feliratkozás és automatikus letöltés' + - 'Dedikált mobil alkalmazások (Android, iOS)' + + first_steps: + - 'Nyisd meg az audiobooks.DOMAIN címet a böngészőben' + - 'Hozd létre az admin fiókot az első megnyitáskor' + - 'Add hozzá a könyvtárakat (/audiobooks és/vagy /podcasts)' + - 'Várd meg az automatikus szkennelést' + - 'Telepítsd az Audiobookshelf alkalmazást a telefonodra' + + prerequisites: + - 'Külső HDD szükséges a hangoskönyvek tárolásához' + - 'Hangoskönyvek mappákba rendezve (pl. Szerző/Könyv/)' + +# --- Controller-side health probe --- +healthcheck: + checks: + - type: api + port: 80 + path: "/healthcheck" + expect: + status: 200 + +# --- English copy (localisation slice 5, R-560) -------------------------------------------- +# The Hungarian above is UNCHANGED. A box on English reads this block field by field; a missing +# field shows the Hungarian one; a controller older than 0.257.0 ignores the block entirely. +i18n: + en: + description: 'An audiobook and podcast server' + app_info: + tagline: 'An audiobook and podcast library, player and sync' + use_cases: + - 'Sort and play your audiobooks and podcasts' + - 'Details arrive on their own - covers, descriptions, chapters' + - 'Carry on where you stopped (it syncs between devices)' + - 'Subscribe to a podcast and let it download itself' + - 'Apps of its own for phones (Android, iOS)' + first_steps: + - 'Open audiobooks.DOMAIN in your browser' + - 'Create the admin account the first time you open it' + - 'Add your libraries (/audiobooks and/or /podcasts)' + - 'Wait for the first scan to finish' + - 'Install the Audiobookshelf app on your phone' + prerequisites: + - 'An external hard drive is needed to keep the audiobooks on' + - 'Audiobooks sorted into folders (Author/Book/, for example)' + deploy_fields: + - env_var: DOMAIN + label: 'Domain' + description: 'The server domain name' + - env_var: SUBDOMAIN + label: 'Subdomain' + description: 'The subdomain this app answers on' + - env_var: HDD_PATH + label: 'Audiobook library path' + description: 'The path to the external hard drive' + placeholder: '/mnt/felhom-drives/hdd_1' diff --git a/templates/audiobookshelf/steps/8db6e47fe3ce3a65.yml b/templates/audiobookshelf/steps/8db6e47fe3ce3a65.yml new file mode 100644 index 0000000..a41a7b1 --- /dev/null +++ b/templates/audiobookshelf/steps/8db6e47fe3ce3a65.yml @@ -0,0 +1,61 @@ +# Audiobookshelf - Hangoskönyv és podcast kezelő szerver +# Domain: ${SUBDOMAIN}.${DOMAIN} +# Database: None (file-based) +# RAM: ~100M (mem_limit: 512M) | Pi-compatible: Yes +# +# Environment variables: +# DOMAIN - Your domain (e.g., demo-felhom.eu) +# USERDATA_PATH - Ügyfél-tartalom gyökér (/userdata) +# +# Storage layout (felhom userdata convention): +# Hangoskönyvek → ${USERDATA_PATH}/media/audiobooks (írható) +# Podcastok → ${USERDATA_PATH}/media/podcasts (írható) +# Run-identity: ROOT (fallback). user "1000:1000" was tried but the image creates its /metadata named +# volume as root at init and fails (`EACCES mkdir /metadata/logs`) when pinned to 1000. So it runs as +# root and relies on the setgid 2775 userdata dirs (files land group 1000 → FileBrowser can browse/read). +# (Verified live; see REPORT.) + +services: + audiobookshelf: + image: ghcr.io/advplyr/audiobookshelf:2.36.1 + container_name: audiobookshelf + restart: unless-stopped + # Runs as root (see note above). Restore an escalation boundary: block SUID-based privilege + # escalation. Full cap_drop is NOT applied — the image's root-init needs file-ownership caps to + # set up /metadata, and dropping them reproduces the EACCES failure we hit pinning user:1000. + security_opt: + - no-new-privileges:true + environment: + - TZ=Europe/Budapest + volumes: + - audiobookshelf_config:/config + - audiobookshelf_metadata:/metadata + - ${USERDATA_PATH}/media/audiobooks:/audiobooks + - ${USERDATA_PATH}/media/podcasts:/podcasts + networks: + - traefik-public + deploy: + resources: + limits: + memory: 512M + healthcheck: + test: ["CMD", "wget", "--spider", "-q", "http://127.0.0.1:80/healthcheck"] + interval: 30s + timeout: 5s + retries: 3 + start_period: 30s + labels: + - "traefik.enable=true" + - "traefik.http.routers.audiobookshelf.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)" + - "traefik.http.routers.audiobookshelf.entrypoints=websecure" + - "traefik.http.routers.audiobookshelf.tls=true" + - "traefik.http.routers.audiobookshelf.tls.certresolver=letsencrypt" + - "traefik.http.services.audiobookshelf.loadbalancer.server.port=80" + +volumes: + audiobookshelf_config: + audiobookshelf_metadata: + +networks: + traefik-public: + external: true