7425ebd6b2
{'audiobookshelf': 'ghcr.io/advplyr/audiobookshelf:2.36.1'} -> {'audiobookshelf': 'ghcr.io/advplyr/audiobookshelf:2.37.1'}
The ONLY image move in this commit. Written by upgrade-test.py --write-ladder (gates rc=0):
- bench LXC 9401 (harness v4): the seed read back before and after; 10-minute memory watch: audiobookshelf anon 10.5 % | migration: [2Kaudiobookshelf | [2026-09-30 13:52:16.057] INFO: [MigrationManager] No migr;
0 kills, 0 restarts; the abort starts and serves the data;
- box 9202 (controller 0.283.1, the product's guarded Update, drill catalog): done in 24.6 s, the seed
read back through the app's own front door.
Evidence: felhom.eu/documentation/audits/pg-last-six-2026-09-30/F/ and .../box/audiobookshelf/
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
62 lines
2.3 KiB
YAML
62 lines
2.3 KiB
YAML
# Audiobookshelf - Hangoskönyv és podcast kezelő szerver
|
|
# Domain: ${SUBDOMAIN}.${DOMAIN}
|
|
# Database: None (file-based)
|
|
# RAM: ~100M (mem_limit: 512M) | Pi-compatible: Yes
|
|
#
|
|
# Environment variables:
|
|
# DOMAIN - Your domain (e.g., demo-felhom.eu)
|
|
# USERDATA_PATH - Ügyfél-tartalom gyökér (<namespace>/userdata)
|
|
#
|
|
# Storage layout (felhom userdata convention):
|
|
# Hangoskönyvek → ${USERDATA_PATH}/media/audiobooks (írható)
|
|
# Podcastok → ${USERDATA_PATH}/media/podcasts (írható)
|
|
# Run-identity: ROOT (fallback). user "1000:1000" was tried but the image creates its /metadata named
|
|
# volume as root at init and fails (`EACCES mkdir /metadata/logs`) when pinned to 1000. So it runs as
|
|
# root and relies on the setgid 2775 userdata dirs (files land group 1000 → FileBrowser can browse/read).
|
|
# (Verified live; see REPORT.)
|
|
|
|
services:
|
|
audiobookshelf:
|
|
image: ghcr.io/advplyr/audiobookshelf:2.37.1
|
|
container_name: audiobookshelf
|
|
restart: unless-stopped
|
|
# Runs as root (see note above). Restore an escalation boundary: block SUID-based privilege
|
|
# escalation. Full cap_drop is NOT applied — the image's root-init needs file-ownership caps to
|
|
# set up /metadata, and dropping them reproduces the EACCES failure we hit pinning user:1000.
|
|
security_opt:
|
|
- no-new-privileges:true
|
|
environment:
|
|
- TZ=Europe/Budapest
|
|
volumes:
|
|
- audiobookshelf_config:/config
|
|
- audiobookshelf_metadata:/metadata
|
|
- ${USERDATA_PATH}/media/audiobooks:/audiobooks
|
|
- ${USERDATA_PATH}/media/podcasts:/podcasts
|
|
networks:
|
|
- traefik-public
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 512M
|
|
healthcheck:
|
|
test: ["CMD", "wget", "--spider", "-q", "http://127.0.0.1:80/healthcheck"]
|
|
interval: 30s
|
|
timeout: 5s
|
|
retries: 3
|
|
start_period: 30s
|
|
labels:
|
|
- "traefik.enable=true"
|
|
- "traefik.http.routers.audiobookshelf.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
|
|
- "traefik.http.routers.audiobookshelf.entrypoints=websecure"
|
|
- "traefik.http.routers.audiobookshelf.tls=true"
|
|
- "traefik.http.routers.audiobookshelf.tls.certresolver=letsencrypt"
|
|
- "traefik.http.services.audiobookshelf.loadbalancer.server.port=80"
|
|
|
|
volumes:
|
|
audiobookshelf_config:
|
|
audiobookshelf_metadata:
|
|
|
|
networks:
|
|
traefik-public:
|
|
external: true
|