# ============================================================================= # stacks.env — mediabox master operator env # host path: /srv/secrets/stacks.env (root:root, 0600) # # THIS IS THE MEDIA BOX'S OWN FILE. It is deliberately NOT shared with, or # mounted from, arrsstack. One host, one secrets file. The canonical copy of # every value lives in Vaultwarden; this is the runtime copy. # # Three tiers, same convention as arrsstack: # [OPERATOR] secrets Claude loads to operate the host; never emitted into # a container env slice # [VALUES] flat, DEDUPED KEY=value — define each variable exactly once # [MANIFEST] #@stack lines mapping a stack -> the vars it needs # # Load with: set -a; . /srv/secrets/stacks.env; set +a # # NOTE: NAS credentials are NOT in this file. fstab needs them at mount time, # which happens long before Docker exists, so they live in /etc/cifs/*.cred # (0600) instead. That file is created EMPTY by the autoinstall and filled in # post-boot over the MCP, so the password never touches removable media. # # This example file carries placeholders only. 10-secrets.sh seeds the real # file from it and thereafter only ever ADDS missing keys. # ============================================================================= # ----- [OPERATOR] — loaded for Claude's use; NEVER written into a stack slice ----- # (none yet on this host) # ----- [VALUES] — flat, deduplicated. Define each variable exactly once. ----- TZ=America/New_York # shell-mcp (native, replaces the mediabox-mcp SSH proxy on arrsstack). # Use the SAME value that arrsstack's stacks.env already holds — the Claude # connector entry and the NPM cert do not change during the cutover, so the # token should not either. Copy it across; do not mint a new one. MEDIABOX_MCP_BEARER_TOKEN=FILL_ME # plex PLEX_ADVERTISE_URL=http://10.0.1.20:32400 # ----- [MANIFEST] — stack -> vars it needs (comments; genenv.sh parses these) ----- #@stack shell-mcp = MEDIABOX_MCP_BEARER_TOKEN TZ #@stack plex = TZ PLEX_ADVERTISE_URL