mirror of
https://github.com/fscotto/infra.git
synced 2026-09-27 19:03:47 +00:00
Add Atlas media and storage services
This commit is contained in:
@@ -0,0 +1,21 @@
|
||||
# Managed by Ansible. Do not edit manually.
|
||||
[Unit]
|
||||
Description=Rootless Navidrome music server
|
||||
|
||||
[Container]
|
||||
ContainerName=navidrome
|
||||
Image={{ server_navidrome_image }}
|
||||
Network=host
|
||||
EnvironmentFile={{ server_navidrome_env_file }}
|
||||
Volume={{ server_navidrome_data_dir }}:/data
|
||||
Volume={{ server_rclone_music_mountpoint }}:/music:ro
|
||||
SecurityLabelDisable=true
|
||||
|
||||
[Service]
|
||||
ExecStartPre=/usr/bin/mountpoint -q {{ server_rclone_music_mountpoint }}
|
||||
Restart=always
|
||||
RestartSec=10s
|
||||
TimeoutStartSec=900
|
||||
|
||||
[Install]
|
||||
WantedBy=default.target
|
||||
7
ansible/roles/profile_server/templates/navidrome.env.j2
Normal file
7
ansible/roles/profile_server/templates/navidrome.env.j2
Normal file
@@ -0,0 +1,7 @@
|
||||
# Managed by Ansible. Contains a Vault secret; do not edit or copy.
|
||||
ND_DATABASE_URL={{ ('postgres://navidrome:' ~ server_navidrome_db_password ~ '@127.0.0.1:5432/navidrome_db?sslmode=disable') | to_json }}
|
||||
ND_PORT={{ server_navidrome_port }}
|
||||
ND_SCANSCHEDULE="1h"
|
||||
ND_SESSIONTIMEOUT="24h"
|
||||
ND_ENABLETRANSCODING="true"
|
||||
ND_LOGLEVEL="info"
|
||||
@@ -0,0 +1,29 @@
|
||||
[Unit]
|
||||
Description=Read-only Atlas music mount via rclone SFTP
|
||||
Wants=network-online.target
|
||||
After=network-online.target
|
||||
{% if server_atlas_wireguard_unit | length > 0 %}
|
||||
Wants={{ server_atlas_wireguard_unit }}
|
||||
After={{ server_atlas_wireguard_unit }}
|
||||
{% endif %}
|
||||
|
||||
[Service]
|
||||
Type=notify
|
||||
User={{ server_username }}
|
||||
Group={{ server_user_group }}
|
||||
ExecStart=/usr/bin/rclone mount \
|
||||
{{ server_atlas_sftp_remote_name }}:{{ server_atlas_sftp_remote_path }} \
|
||||
{{ server_rclone_music_mountpoint }} \
|
||||
--config {{ server_rclone_config_file }} \
|
||||
--cache-dir {{ server_rclone_music_cache_dir }} \
|
||||
--read-only \
|
||||
--vfs-cache-mode full \
|
||||
--vfs-cache-max-size 15G \
|
||||
--vfs-read-chunk-size 5M \
|
||||
--dir-cache-time 24h
|
||||
ExecStop=-/usr/bin/fusermount3 -uz {{ server_rclone_music_mountpoint }}
|
||||
Restart=on-failure
|
||||
RestartSec=10s
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
9
ansible/roles/profile_server/templates/rclone.conf.j2
Normal file
9
ansible/roles/profile_server/templates/rclone.conf.j2
Normal file
@@ -0,0 +1,9 @@
|
||||
# Managed by Ansible. Authentication uses the separately deployed Vault-backed key.
|
||||
[{{ server_atlas_sftp_remote_name }}]
|
||||
type = sftp
|
||||
host = {{ server_atlas_sftp_host }}
|
||||
user = {{ server_atlas_sftp_username }}
|
||||
port = {{ server_atlas_sftp_port }}
|
||||
key_file = {{ server_atlas_sftp_private_key_file }}
|
||||
known_hosts_file = {{ server_atlas_sftp_known_hosts_file }}
|
||||
shell_type = unix
|
||||
Reference in New Issue
Block a user