Back to :latest + a watchtower service checking daily at 05:00, cleanup
on, ntfy notification to arrsstack-alerts on every update. Rollback net
= Plex's own scheduled DB backups + the NAS media_pc backup. shell-mcp
is a local build, watchtower ignores it.
Same PMS build the database was born on. SQLite schema upgrades are
one-way; a surprise :latest bump no longer gets a vote. Bump the pin
deliberately when choosing to upgrade.
subprocess.run inside the async handler serialized every request behind
the slowest command (found 2026-08-01 when a du wedged the server mid-
migration). Run it in the default thread pool via run_in_executor so
concurrent calls actually run concurrently. Timeout default 30->60,
cap 300->600, schema text matched.
No Windows-side robocopy. Everything on D: (PMS dir, Calibre, Nikola
iPad) is copied to the NAS media_pc share from Linux, Media/ staged via
the SSD, D: formatted ext4 BEFORE Plex first starts, thumbnails live on
/srv/data. Fixes the M3 restore path that pointed at the unmounted
Share. Per Mike 2026-07-31.
Bind mount is now active, not a commented Phase-2 option — Mike's call
2026-07-31 (337 GB is too large for the SSD). Quick Sync confirmed as
the transcode device; NAS account is read-only on the library shares.
NAS account is read-only on the libraries at the Synology side; the ro
mount option is belt-and-braces. media_pc is this box's one write share
(PMS backup, Calibre, Nikola iPad). Per Mike 2026-07-31.
The forward-only decision was reversed: the server identity is now
migrated, not minted. Claiming would destroy the exact thing the
migration exists to preserve.
- remove every PLEX_CLAIM path
- check the six real mount points by exact share name
- refuse to start against an un-remapped database
- refuse to start without ProcessedMachineIdentifier in Preferences.xml
- assert machineIdentifier after start
Runs the stages in order and fails soft. A stage failure must never wedge
boot: there is no keyboard attached to this box, so a machine that comes up
with sshd and a broken GPU driver is recoverable and one that hangs is not.