Files
app-catalog-felhom.eu/templates/audiobookshelf/docker-compose.yml
T
admin 8ddd3c9da5 fix(healthcheck): sweep localhost -> 127.0.0.1 across all 48 templates
BusyBox wget (+ node/python/curl one-shots, incl mealie's socket tuple) resolve
localhost -> IPv6 ::1 with no cross-family fallback; an IPv4-only-binding app
reads docker-unhealthy while serving (vaultwarden, re-run 2026-07-06). Escalates
that instance to the class. Scoped strictly to healthcheck test: lines
(diff-reviewed: no env/config/label changed; .felhom.yml already clean). New
REUSE.md convention row.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PSK5g6qYLknKj8u3QAFEr6
2026-07-06 20:25:54 +02:00

62 lines
2.3 KiB
YAML

# Audiobookshelf - Hangoskönyv és podcast kezelő szerver
# Domain: ${SUBDOMAIN}.${DOMAIN}
# Database: None (file-based)
# RAM: ~100M (mem_limit: 512M) | Pi-compatible: Yes
#
# Environment variables:
# DOMAIN - Your domain (e.g., demo-felhom.eu)
# USERDATA_PATH - Ügyfél-tartalom gyökér (<namespace>/userdata)
#
# Storage layout (felhom userdata convention):
# Hangoskönyvek → ${USERDATA_PATH}/media/audiobooks (írható)
# Podcastok → ${USERDATA_PATH}/media/podcasts (írható)
# Run-identity: ROOT (fallback). user "1000:1000" was tried but the image creates its /metadata named
# volume as root at init and fails (`EACCES mkdir /metadata/logs`) when pinned to 1000. So it runs as
# root and relies on the setgid 2775 userdata dirs (files land group 1000 → FileBrowser can browse/read).
# (Verified live; see REPORT.)
services:
audiobookshelf:
image: ghcr.io/advplyr/audiobookshelf:2.19.5
container_name: audiobookshelf
restart: unless-stopped
# Runs as root (see note above). Restore an escalation boundary: block SUID-based privilege
# escalation. Full cap_drop is NOT applied — the image's root-init needs file-ownership caps to
# set up /metadata, and dropping them reproduces the EACCES failure we hit pinning user:1000.
security_opt:
- no-new-privileges:true
environment:
- TZ=Europe/Budapest
volumes:
- audiobookshelf_config:/config
- audiobookshelf_metadata:/metadata
- ${USERDATA_PATH}/media/audiobooks:/audiobooks
- ${USERDATA_PATH}/media/podcasts:/podcasts
networks:
- traefik-public
deploy:
resources:
limits:
memory: 512M
healthcheck:
test: ["CMD", "wget", "--spider", "-q", "http://127.0.0.1:80/healthcheck"]
interval: 30s
timeout: 5s
retries: 3
start_period: 30s
labels:
- "traefik.enable=true"
- "traefik.http.routers.audiobookshelf.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
- "traefik.http.routers.audiobookshelf.entrypoints=websecure"
- "traefik.http.routers.audiobookshelf.tls=true"
- "traefik.http.routers.audiobookshelf.tls.certresolver=letsencrypt"
- "traefik.http.services.audiobookshelf.loadbalancer.server.port=80"
volumes:
audiobookshelf_config:
audiobookshelf_metadata:
networks:
traefik-public:
external: true