Autoinstall lays down a thin base (sshd, key, DHCP, Docker CE, /srv) and hands
off to this repo on first boot. Everything interesting stays in git so it is
reviewable and re-runnable, rather than frozen onto a USB nobody can diff.
Stages, all idempotent:
00-preflight asserts hardware/BIOS state, changes nothing. Catches a BIOS
update having silently re-enabled Secure Boot, which would stop
the NVIDIA DKMS module loading on a box with no keyboard.
10-secrets ADD-ONLY seeder for /srv/secrets/stacks.env. Never overwrites an
existing key. Verified against a pre-populated file: existing
values, unrelated keys, the operator tier and existing manifest
lines all survive byte-for-byte; a second run is a no-op.
20-cifs the 8 shares Plex actually uses (Share is excluded, it is not a
library root). \040 escaping, nofail + x-systemd.automount +
_netdev. Managed-block rewrite verified not to duplicate or to
drop the root fstab entry.
30-nvidia nvidia-driver-580 explicitly: 580 is the LAST branch supporting
Pascal, and the -open modules need Turing+. Pins against newer
branches. Not in late-commands because DKMS needs the installed
kernel, not the installer's.
40-shell-mcp builds the native MCP locally for amd64; refuses to finish
unless /sse returns 401 without a token.
50-plex run by hand: PLEX_CLAIM expires in 4 minutes. Refuses to start
against missing mounts and disables autoEmptyTrash, which with
read-write NAS credentials is the most dangerous default here.
shell-mcp was built on arm64 originally. It builds clean on amd64 (whole dep
tree resolves to prebuilt manylinux x86_64 wheels, no compiler needed), but
dependencies are now pinned - the original installed mcp/starlette/uvicorn
unpinned and starlette has since gone 1.x. Port moved to 8103 so NPM host 42
can simply be repointed, and the tool description now says media box rather
than arrsstack.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
44 lines
2.0 KiB
Bash
44 lines
2.0 KiB
Bash
# =============================================================================
|
|
# stacks.env — mediabox master operator env
|
|
# host path: /srv/secrets/stacks.env (root:root, 0600)
|
|
#
|
|
# THIS IS THE MEDIA BOX'S OWN FILE. It is deliberately NOT shared with, or
|
|
# mounted from, arrsstack. One host, one secrets file. The canonical copy of
|
|
# every value lives in Vaultwarden; this is the runtime copy.
|
|
#
|
|
# Three tiers, same convention as arrsstack:
|
|
# [OPERATOR] secrets Claude loads to operate the host; never emitted into
|
|
# a container env slice
|
|
# [VALUES] flat, DEDUPED KEY=value — define each variable exactly once
|
|
# [MANIFEST] #@stack lines mapping a stack -> the vars it needs
|
|
#
|
|
# Load with: set -a; . /srv/secrets/stacks.env; set +a
|
|
#
|
|
# NOTE: NAS credentials are NOT in this file. fstab needs them at mount time,
|
|
# which happens long before Docker exists, so they live in /etc/cifs/*.cred
|
|
# (0600) instead. That file is created EMPTY by the autoinstall and filled in
|
|
# post-boot over the MCP, so the password never touches removable media.
|
|
#
|
|
# This example file carries placeholders only. 10-secrets.sh seeds the real
|
|
# file from it and thereafter only ever ADDS missing keys.
|
|
# =============================================================================
|
|
|
|
# ----- [OPERATOR] — loaded for Claude's use; NEVER written into a stack slice -----
|
|
# (none yet on this host)
|
|
|
|
# ----- [VALUES] — flat, deduplicated. Define each variable exactly once. -----
|
|
TZ=America/New_York
|
|
|
|
# shell-mcp (native, replaces the mediabox-mcp SSH proxy on arrsstack).
|
|
# Use the SAME value that arrsstack's stacks.env already holds — the Claude
|
|
# connector entry and the NPM cert do not change during the cutover, so the
|
|
# token should not either. Copy it across; do not mint a new one.
|
|
MEDIABOX_MCP_BEARER_TOKEN=FILL_ME
|
|
|
|
# plex
|
|
PLEX_ADVERTISE_URL=http://10.0.1.20:32400
|
|
|
|
# ----- [MANIFEST] — stack -> vars it needs (comments; genenv.sh parses these) -----
|
|
#@stack shell-mcp = MEDIABOX_MCP_BEARER_TOKEN TZ
|
|
#@stack plex = TZ PLEX_ADVERTISE_URL
|