diff --git a/README.md b/README.md index be5d8b5..baffa4f 100644 --- a/README.md +++ b/README.md @@ -20,10 +20,12 @@ bootstrap.sh orchestrator — runs the stages, fails soft scripts/ 00-preflight.sh asserts hardware/BIOS state. Changes nothing. 10-secrets.sh idempotent ADD-ONLY seeder for /srv/secrets/stacks.env - 20-cifs.sh the 8 NAS mounts (--verify mode included) + 20-cifs.sh the 6 NAS mounts, named exactly as the DB stores them 30-nvidia.sh NVIDIA 580 + container toolkit 40-shell-mcp.sh builds and starts the native shell-mcp - 50-plex.sh Plex. Run BY HAND — needs a live claim token. + 50-plex.sh Plex against the MIGRATED data dir. No claim token. + 60-media-relocate.sh optional, post-soak: move the 337 GB preview cache +migration/ remap.sql, migrate-db.sh, gen-preferences.ps1, README.md shell-mcp/ amd64 build of the MCP server (server.py, Dockerfile, docker-compose.yml, pinned requirements.txt) plex/docker-compose.yml Plex service definition @@ -51,9 +53,11 @@ continues; the systemd unit declares `SuccessExitStatus=0 1` so a bad stage can never wedge boot. There is no keyboard attached to this machine. **Secrets never ride on removable media.** The CIFS credentials file is created -*empty* by the autoinstall and filled in post-boot over the MCP. `PLEX_CLAIM` -tokens expire in four minutes and are passed as a one-shot environment variable, -never written to disk or committed. +*empty* by the autoinstall and filled in post-boot over the MCP. + +**No claim token, ever.** The migration preserves `MachineIdentifier`, so this +is the existing server rather than a new one. Claiming would discard shared +users and every client registration. **One secrets file per host.** This box has its own `/srv/secrets/stacks.env`, using the same `[OPERATOR]` / `[VALUES]` / `[MANIFEST]` tiering as arrsstack, but