18 Commits
Author SHA1 Message Date
thethreemagi 59c84a0564 plex: add .env.example documenting the watchtower ntfy credential 2026-08-04 04:45:09 +01:00
thethreemagi 9964b36832 plex: move the watchtower ntfy URL out of compose into a gitignored .env, and sync the opt-in watchtower changes that were only on the host 2026-08-04 04:44:57 +01:00
thethreemagi d279a73e5b shell-mcp: exclude from watchtower — local build, no registry; its 05:00 pull attempt 401'd and ntfy'd 2026-08-02 13:10:01 +01:00
thethreemagi 658ea65627 migration: mark executed 2026-08-01, record deviations from the written procedure 2026-08-02 06:10:30 +01:00
thethreemagi a80f96b9a7 watchtower: pin DOCKER_API_VERSION — v1.7.1's client defaults to 1.25, below Engine 29's minimum of 1.40 2026-08-02 04:02:59 +01:00
thethreemagi 43a4324885 plex: auto-update via watchtower (Mike's call 2026-08-02, supersedes the pin)
Back to :latest + a watchtower service checking daily at 05:00, cleanup
on, ntfy notification to arrsstack-alerts on every update. Rollback net
= Plex's own scheduled DB backups + the NAS media_pc backup. shell-mcp
is a local build, watchtower ignores it.
2026-08-02 03:58:43 +01:00
thethreemagi ce2b49ef73 plex: pin image to 1.43.3.10828-ls316 (the exact running version)
Same PMS build the database was born on. SQLite schema upgrades are
one-way; a surprise :latest bump no longer gets a vote. Bump the pin
deliberately when choosing to upgrade.
2026-08-02 03:47:42 +01:00
thethreemagi d6760a709d shell-mcp: don't block the event loop; honor longer timeouts
subprocess.run inside the async handler serialized every request behind
the slowest command (found 2026-08-01 when a du wedged the server mid-
migration). Run it in the default thread pool via run_in_executor so
concurrent calls actually run concurrently. Timeout default 30->60,
cap 300->600, schema text matched.
2026-08-02 03:45:46 +01:00
thethreemagi 973c4bc44b bootstrap: post first-boot result to ntfy arrsstack-alerts (best-effort)
The box announces itself — publish path verified from 10.0.1.20 with a
200 on 2026-08-01. Never blocks or fails the bootstrap.
2026-08-01 15:02:28 +01:00
thethreemagi 2438e715fc bootstrap: remaining-steps text matches the 2026-07-31 flow (copy-off D:, format before Plex) 2026-07-31 19:46:12 +01:00
thethreemagi bc1e3d78d3 migration: new sequence — D: is the backup, copy-off to media_pc, format before first start
No Windows-side robocopy. Everything on D: (PMS dir, Calibre, Nikola
iPad) is copied to the NAS media_pc share from Linux, Media/ staged via
the SSD, D: formatted ext4 BEFORE Plex first starts, thumbnails live on
/srv/data. Fixes the M3 restore path that pointed at the unmounted
Share. Per Mike 2026-07-31.
2026-07-31 19:35:52 +01:00
thethreemagi 579787c8db plex: Media/ cache lives on the 3TB ext4 disk from day one, not the SSD
Bind mount is now active, not a commented Phase-2 option — Mike's call
2026-07-31 (337 GB is too large for the SSD). Quick Sync confirmed as
the transcode device; NAS account is read-only on the library shares.
2026-07-31 19:34:52 +01:00
thethreemagi 6f0605a4fd 20-cifs: seven shares — six library mounts read-only, media_pc read-write
NAS account is read-only on the libraries at the Synology side; the ro
mount option is belt-and-braces. media_pc is this box's one write share
(PMS backup, Calibre, Nikola iPad). Per Mike 2026-07-31.
2026-07-31 19:34:26 +01:00
thethreemagi 6f6d563569 README: 6 mounts not 8, migration/ in the layout, no-claim rule 2026-07-31 17:56:59 +01:00
thethreemagi 7017e9f4d5 bootstrap: closing notes point at the migration, not a claim token
Step 3 was "claim the server". That is now the one thing that must
not happen. It now points at migration/README.md M3/M4.
2026-07-31 17:56:31 +01:00
thethreemagi 9a3e824b90 50-plex: drop claim flow, gate on migrated DB and preserved identity
The forward-only decision was reversed: the server identity is now
migrated, not minted. Claiming would destroy the exact thing the
migration exists to preserve.

- remove every PLEX_CLAIM path
- check the six real mount points by exact share name
- refuse to start against an un-remapped database
- refuse to start without ProcessedMachineIdentifier in Preferences.xml
- assert machineIdentifier after start
2026-07-31 17:56:10 +01:00
thethreemagi 965f5f5ba0 Add first-boot orchestrator
Runs the stages in order and fails soft. A stage failure must never wedge
boot: there is no keyboard attached to this box, so a machine that comes up
with sshd and a broken GPU driver is recoverable and one that hangs is not.
2026-07-27 23:00:22 +01:00
thethreemagi 490003baf6 Initial commit 2026-07-27 22:59:48 +01:00