134 lines
6.2 KiB
YAML
134 lines
6.2 KiB
YAML
services:
|
|
plex:
|
|
# AUTO-UPDATE — Mike's call 2026-08-02, superseding the short-lived pin.
|
|
# :latest + the watchtower service below (daily 05:00 check). Remember:
|
|
# SQLite schema upgrades are ONE-WAY. The rollback net is Plex's own
|
|
# scheduled database backups (Settings > Scheduled Tasks, default every
|
|
# 3 days) and the NAS media_pc backup. Watchtower ntfys every update.
|
|
image: lscr.io/linuxserver/plex:latest
|
|
container_name: plex
|
|
restart: unless-stopped
|
|
|
|
# NOT OPTIONAL. Plex's local discovery (GDM) and client auto-detection rely
|
|
# on broadcast traffic that a bridge network silently eats. (DLNA is off on
|
|
# this server, so discovery — not DLNA — is the reason.) This is also why
|
|
# Plex does not sit behind NPM like everything else here: proxy host 17
|
|
# already points plex.thewichersfamily.com at 10.0.1.20:32400 and needs no
|
|
# change, because the IP does not move.
|
|
network_mode: host
|
|
|
|
environment:
|
|
- PUID=3000 # MUST equal uid= on the CIFS mounts
|
|
- PGID=3000 # MUST equal gid= on the CIFS mounts
|
|
- TZ=${TZ:-America/New_York}
|
|
# VERSION=docker stays even with auto-update: the container must never
|
|
# self-update INSIDE (those updates evaporate on recreate). Watchtower
|
|
# updates by replacing the image, which is the durable path.
|
|
- VERSION=docker
|
|
# No PLEX_CLAIM. The migration carries MachineIdentifier,
|
|
# ProcessedMachineIdentifier and the online token across in
|
|
# Preferences.xml, so this server IS the existing server — already
|
|
# claimed, shared users intact, clients not needing to re-add it.
|
|
# Claiming would create a NEW server identity and throw that away.
|
|
|
|
devices:
|
|
# Quick Sync on the UHD 630 — DECIDED 2026-07-31. No session cap and
|
|
# better HDR tone mapping than the Pascal-era NVENC on the 1070, and the
|
|
# i915 driver lives in the kernel, so nothing breaks on updates. The
|
|
# GTX 1070 stays free for other work. Requires the BIOS iGPU
|
|
# Multi-Monitor toggle or /dev/dri does not exist.
|
|
- /dev/dri:/dev/dri
|
|
|
|
group_add:
|
|
# Render node is root:render and PGID 3000 is not in that group.
|
|
# Resolved from the live host by 50-plex.sh — the gid differs across
|
|
# distro releases, so do not hardcode it.
|
|
- "${RENDER_GID:-993}"
|
|
|
|
volumes:
|
|
# ---- Plex data directory (SSD): database + Metadata, NOT Media/ -------
|
|
# The SQLite database is the most latency-sensitive thing on the box and
|
|
# belongs on flash. Metadata/ (25 GB of posters) rides along. The 337 GB
|
|
# Media/ preview cache does NOT — see the bind below.
|
|
- type: bind
|
|
source: /srv/plex/config
|
|
target: /config
|
|
|
|
# ---- Preview/thumbnail cache on the 3 TB ext4 disk — NOT the SSD ------
|
|
# Mike's call 2026-07-31: 337 GB is too large for the 500 GB SSD, so
|
|
# Media/ lives on /srv/data (the former D:, now ext4) from day one.
|
|
# Long-form syntax deliberately: the target path contains spaces, which
|
|
# the short "a:b" form handles badly. Docker orders mounts by target
|
|
# depth, so this correctly lands inside the /config mount above.
|
|
#
|
|
# Plex does NOT support relocating this directory natively — this bind
|
|
# mount is the mechanism. After first start, force thumbnail generation
|
|
# on one title to prove writes succeed across the filesystem boundary
|
|
# (EXDEV) — that failure mode can only be tested, not reasoned about.
|
|
- type: bind
|
|
source: /srv/data/plex-media
|
|
target: /config/Library/Application Support/Plex Media Server/Media
|
|
|
|
# ---- NAS media, mounted at the SAME paths the database stores ---------
|
|
# The remap rewrites \\korval\X -> /mnt/nas/X, so the container must see
|
|
# exactly /mnt/nas/X. Six separate entries rather than one bind of
|
|
# /mnt/nas, because a plain bind does not carry the submounts beneath it.
|
|
# Read-only here AND at the mount AND at the Synology — the mediabox NAS
|
|
# account has no write permission on the library shares. media_pc (the
|
|
# box's write share) is deliberately not exposed to Plex.
|
|
- type: bind
|
|
source: /mnt/nas/media
|
|
target: /mnt/nas/media
|
|
read_only: true
|
|
- type: bind
|
|
source: /mnt/nas/Radio Shows
|
|
target: /mnt/nas/Radio Shows
|
|
read_only: true
|
|
- type: bind
|
|
source: /mnt/nas/Education Videos
|
|
target: /mnt/nas/Education Videos
|
|
read_only: true
|
|
- type: bind
|
|
source: /mnt/nas/Health
|
|
target: /mnt/nas/Health
|
|
read_only: true
|
|
- type: bind
|
|
source: /mnt/nas/Home Movies
|
|
target: /mnt/nas/Home Movies
|
|
read_only: true
|
|
- type: bind
|
|
source: /mnt/nas/Pictures
|
|
target: /mnt/nas/Pictures
|
|
read_only: true
|
|
|
|
tmpfs:
|
|
# Matches TranscoderTempDirectory=/transcode in the generated
|
|
# Preferences.xml. Transcodes are throwaway; keeping them in RAM saves
|
|
# a great deal of SSD write wear. 4G of 16G, capped so a pathological
|
|
# transcode cannot pressure the rest of the system.
|
|
- /transcode:rw,size=4g,mode=1777
|
|
|
|
watchtower:
|
|
# Auto-updater — checks daily at 05:00 local, pulls newer images,
|
|
# recreates the container with identical settings, prunes old images,
|
|
# and ntfys arrsstack-alerts about anything it did. Local builds
|
|
# (shell-mcp) have no registry to compare against and are ignored.
|
|
image: containrrr/watchtower
|
|
container_name: watchtower
|
|
restart: unless-stopped
|
|
environment:
|
|
- TZ=${TZ:-America/New_York}
|
|
# Watchtower v1.7.1's bundled docker client defaults to API 1.25 and
|
|
# its version negotiation fails against Engine 29 (min API 1.40),
|
|
# leaving the container in a crash loop. Pinning the API version is
|
|
# the documented workaround. 1.44 is safely inside the supported
|
|
# window on this host (server 1.55, min 1.40).
|
|
- DOCKER_API_VERSION=1.44
|
|
- WATCHTOWER_SCHEDULE=0 0 5 * * *
|
|
- WATCHTOWER_CLEANUP=true
|
|
- WATCHTOWER_NOTIFICATIONS=shoutrrr
|
|
- WATCHTOWER_NOTIFICATION_URL=ntfy://ntfy.thewichersfamily.com/arrsstack-alerts
|
|
- WATCHTOWER_NOTIFICATION_TEMPLATE={{range .}}{{.Message}}{{println}}{{end}}
|
|
volumes:
|
|
- /var/run/docker.sock:/var/run/docker.sock
|