402 lines
18 KiB
Go
402 lines
18 KiB
Go
// Package config loads the gateway's settings from the environment.
|
|
package config
|
|
|
|
import (
|
|
"encoding/json"
|
|
"fmt"
|
|
"os"
|
|
"strconv"
|
|
"strings"
|
|
"time"
|
|
_ "time/tzdata"
|
|
|
|
"github.com/ponzischeme89/memby/server/internal/emby"
|
|
)
|
|
|
|
type Config struct {
|
|
ListenAddr string
|
|
|
|
// EmbyURL is how the gateway itself reaches Emby (may be a private/docker address).
|
|
EmbyURL string
|
|
// EmbyPublicURL is the address handed to TV clients for direct video playback.
|
|
// Defaults to EmbyURL; set it when the gateway talks to Emby over a network the
|
|
// TVs cannot reach.
|
|
EmbyPublicURL string
|
|
// EmbyMediaURL is the address the gateway reads *media bytes* from, which is a
|
|
// different question from how it reads metadata and is the only place the difference
|
|
// costs anything.
|
|
//
|
|
// Credits detection is the one thing on the server side that opens a media file, and it
|
|
// does so with ranged reads over HTTP. A metadata call is a few kilobytes and does not
|
|
// care which way it is routed; a scan is megabytes, and where EmbyURL is a public
|
|
// hostname — which it legitimately may be, since the gateway and Emby need not share a
|
|
// network — every one of those ranged reads leaves the host for the internet-facing
|
|
// edge, pays TLS, and comes back in through a reverse proxy that is free to buffer the
|
|
// response and discard the range economy entirely.
|
|
//
|
|
// So this is stated separately rather than inferred: there is no way to look at a URL
|
|
// and tell whether it happens to resolve locally. Unset, it falls back to EmbyURL and
|
|
// nothing changes.
|
|
EmbyMediaURL string
|
|
|
|
DatabaseURL string
|
|
RedisURL string
|
|
|
|
// ClientName is reported to Emby in the X-Emby-Authorization header, so sessions
|
|
// show up as this in Emby's dashboard. It is deliberately not the app's own name:
|
|
// the header travels to whatever Emby does with its logs, and the product name has
|
|
// no business being the thing that identifies a client to a third party.
|
|
ClientName string
|
|
|
|
// GatewayClientName is reported instead for a request the gateway makes on its own
|
|
// behalf — the library sync, the health probe, device cleanup, and an operator
|
|
// signing into the admin console or the web installer. Those are the server asking,
|
|
// and reporting them as a television made Emby's device list claim a set that does
|
|
// not exist in the house.
|
|
GatewayClientName string
|
|
|
|
HomeTTL time.Duration
|
|
ItemTTL time.Duration
|
|
SearchTTL time.Duration
|
|
ScreensaverTTL time.Duration
|
|
SessionTTL time.Duration
|
|
// SessionIdleExpiry retires gateway tokens that go unused for this long.
|
|
SessionIdleExpiry time.Duration
|
|
// RecommendTTL is how long computed recommendation rows stay warm. Long, because
|
|
// taste moves slowly and each rebuild costs several Emby queries.
|
|
RecommendTTL time.Duration
|
|
// RecommendTimeout bounds a background rebuild, which fans out further than a
|
|
// normal request and so needs more headroom than UpstreamTimeout.
|
|
RecommendTimeout time.Duration
|
|
// MagicPoolTTL is how long Magic's scored pool stays warm. Shorter than
|
|
// RecommendTTL, which is a daily rotation nobody is waiting on: this one is
|
|
// rebuilt in front of somebody standing at a player with the film paused
|
|
// behind a loading panel, and a household that has just acquired something
|
|
// should be able to be handed it the same evening.
|
|
MagicPoolTTL time.Duration
|
|
// RecommendationWeights is an optional JSON overlay on the weighted defaults.
|
|
RecommendationWeights string
|
|
// RemoteConfig is the complete, validated presentation document served to TVs.
|
|
// It is app-scoped and intentionally contains no account, playback or routing state.
|
|
RemoteConfig RemoteConfig
|
|
|
|
UpstreamTimeout time.Duration
|
|
|
|
// SlowRequestThreshold is how long a request has to take before its log line
|
|
// carries a stage breakdown. Fast requests deliberately carry none: it is the one
|
|
// field on the line that varies in width, and a column of them on every /v1/status
|
|
// poll would make the thing it exists to reveal harder to find, not easier.
|
|
SlowRequestThreshold time.Duration
|
|
|
|
// EmbyHealthInterval paces the reachability probe behind the "server not responding"
|
|
// and "back online" banners. One probe per gateway, not per TV. Zero disables it.
|
|
EmbyHealthInterval time.Duration
|
|
|
|
// AdminToken guards the operator interface. Empty disables /admin entirely, so an
|
|
// unconfigured deployment cannot leave it exposed.
|
|
AdminToken string
|
|
|
|
// AdminUIURL is where the console's own container serves its built assets. It is an
|
|
// internal compose address: memby-admin is never published, and the gateway proxies
|
|
// /admin to it so the console shares this origin, this cookie and this ingress.
|
|
// Blank disables the console while leaving the /admin API intact for automation.
|
|
AdminUIURL string
|
|
|
|
// PublicURL is the externally reachable Memby gateway address used in update links.
|
|
PublicURL string
|
|
// ReleaseDir persists signed APKs published by CI.
|
|
ReleaseDir string
|
|
// ReleasePublishToken authorizes the CI-only release upload endpoint. It is separate
|
|
// from AdminToken so a compromised build runner cannot change maintenance settings.
|
|
ReleasePublishToken string
|
|
|
|
// SyncInterval is how often the library import runs. Zero disables the schedule.
|
|
SyncInterval time.Duration
|
|
// SyncTimeout bounds one import; a full pass over a large library is slow.
|
|
SyncTimeout time.Duration
|
|
// SyncOnStart triggers an incremental import at boot.
|
|
SyncOnStart bool
|
|
// SyncUserID / SyncAPIKey are an optional Emby service account for imports. Without
|
|
// them the newest TV session is borrowed instead.
|
|
SyncUserID string
|
|
SyncAPIKey string
|
|
|
|
// AnalyticsRetention is how long raw row and journey events are kept before pruning.
|
|
// Load enforces a 30-day floor so the per-user history promise cannot be configured away.
|
|
AnalyticsRetention time.Duration
|
|
|
|
// Sonarr is optional. When configured, its local calendar supplies the informational
|
|
// Five-day "Shows airing" home row. The API key never leaves this server.
|
|
SonarrURL string
|
|
SonarrAPIKey string
|
|
SonarrTTL time.Duration
|
|
SonarrLocation *time.Location
|
|
|
|
// SonarrAlertWindow is how long after an episode airs the "aired, coming soon"
|
|
// banner keeps being offered to clients. Zero turns the banners off without
|
|
// touching the five-day schedule row.
|
|
SonarrAlertWindow time.Duration
|
|
|
|
// SonarrWebhookToken guards the Sonarr import/upgrade/rename/delete webhook. Empty
|
|
// means the hook 404s, the stance the Radarr one takes.
|
|
SonarrWebhookToken string
|
|
|
|
// IngestSettleDelay is how long after a webhook the gateway first looks for the file
|
|
// in Emby. Sonarr fires the moment it has moved the file into place and Emby has not
|
|
// scanned it yet, so asking immediately spends a request to learn nothing.
|
|
IngestSettleDelay time.Duration
|
|
|
|
// Radarr is optional. Its calendar supplies the five-day digital movie release row.
|
|
RadarrURL string
|
|
RadarrAPIKey string
|
|
RadarrTTL time.Duration
|
|
RadarrLocation *time.Location
|
|
|
|
// RadarrWebhookToken guards the Radarr "on import" webhook. Empty means the hook
|
|
// 404s, so an unconfigured deployment cannot be fed alerts by anyone who finds it.
|
|
RadarrWebhookToken string
|
|
// RadarrAlertWindow is how long an imported movie keeps being announced to clients.
|
|
// It is a window rather than a one-shot push because the gateway has no connection
|
|
// to a TV that is switched off: a set turned on inside the window still gets the
|
|
// news, and each TV dedupes by alert id. Zero turns the banners off.
|
|
RadarrAlertWindow time.Duration
|
|
|
|
// Bazarr is optional and is what lets a viewer fetch a subtitle a title does not have.
|
|
// It writes the file beside the media, so Emby serves the result and the gateway needs
|
|
// no storage of its own. Unset means the player simply never offers the option.
|
|
BazarrURL string
|
|
BazarrAPIKey string
|
|
// BazarrTTL is how long the movie/series/episode listings are cached. They exist only
|
|
// to turn an Emby item into the *arr id Bazarr keys on, and a household's library does
|
|
// not change between one subtitle search and the next.
|
|
BazarrTTL time.Duration
|
|
// BazarrTimeout bounds a manual search, which queries live subtitle providers and is
|
|
// legitimately slow. It is separate from BazarrTTL because a short HTTP timeout here
|
|
// shows up as "no subtitles found" rather than as an error.
|
|
BazarrTimeout time.Duration
|
|
|
|
// Tracearr is an optional, read-only source of completion, session-length and
|
|
// direct-play signals for the per-user For You area. The public API key stays in
|
|
// the gateway and is never returned to a TV.
|
|
TracearrURL string
|
|
TracearrAPIKey string
|
|
TracearrServerID string
|
|
// Credits detection discovers where an episode's closing credits begin, for the small
|
|
// number of episodes the household is about to watch. It is demand-driven — Tracearr
|
|
// says what is worth scanning — so these settings shape how far ahead of a viewer it
|
|
// prepares, never how much of the library it reads.
|
|
//
|
|
// CreditsEnabled is off by default: it is the only thing in the gateway that reads media
|
|
// bytes, and switching that on is an operator's decision rather than a default.
|
|
CreditsEnabled bool
|
|
// CreditsFFmpeg is the decoder. Absent, the subsystem still runs and still writes
|
|
// markers, on behavioural evidence alone — which on a well-watched show is the better
|
|
// signal anyway.
|
|
CreditsFFmpeg string
|
|
// CreditsPrefetchEpisodes is the first-run look-ahead for an ordinary viewer; velocity
|
|
// moves the actual depth either side of it, and CreditsMaxPrefetch is the ceiling nothing
|
|
// exceeds. The admin console persists later operator choices in app_settings.
|
|
CreditsPrefetchEpisodes int
|
|
CreditsMaxPrefetch int
|
|
// CreditsQueueLimit is the first-run bound on pending candidates. Past it, low-priority
|
|
// speculation is discarded rather than queued.
|
|
CreditsQueueLimit int
|
|
|
|
// TracearrSyncInterval imports recent changed sessions. FullInterval reconciles
|
|
// late/out-of-order updates and deletions without needing a source cursor.
|
|
TracearrSyncInterval time.Duration
|
|
TracearrFullInterval time.Duration
|
|
// Prepared pools rebuild daily at RebuildHour in the configured timezone. The age
|
|
// settings are safety bounds for manual/background fallback paths.
|
|
ForYouMinRebuildAge time.Duration
|
|
ForYouRefreshInterval time.Duration
|
|
ForYouRebuildHour int
|
|
}
|
|
|
|
func Load() (Config, error) {
|
|
remoteConfig, err := loadRemoteConfig(os.Getenv("MEMBY_REMOTE_CONFIG_JSON"))
|
|
if err != nil {
|
|
return Config{}, err
|
|
}
|
|
releasePublishToken, err := secret("MEMBY_RELEASE_PUBLISH_TOKEN")
|
|
if err != nil {
|
|
return Config{}, err
|
|
}
|
|
c := Config{
|
|
ListenAddr: env("MEMBY_LISTEN_ADDR", ":8080"),
|
|
EmbyURL: strings.TrimRight(os.Getenv("MEMBY_EMBY_URL"), "/"),
|
|
EmbyPublicURL: strings.TrimRight(os.Getenv("MEMBY_EMBY_PUBLIC_URL"), "/"),
|
|
EmbyMediaURL: strings.TrimRight(os.Getenv("MEMBY_EMBY_MEDIA_URL"), "/"),
|
|
DatabaseURL: os.Getenv("MEMBY_DATABASE_URL"),
|
|
RedisURL: env("MEMBY_REDIS_URL", "redis://localhost:6379/0"),
|
|
ClientName: env("MEMBY_CLIENT_NAME", "MbyATV"),
|
|
GatewayClientName: env("MEMBY_GATEWAY_CLIENT_NAME", emby.DefaultGatewayClientName),
|
|
HomeTTL: duration("MEMBY_HOME_TTL", 60*time.Second),
|
|
ItemTTL: duration("MEMBY_ITEM_TTL", 10*time.Minute),
|
|
SearchTTL: duration("MEMBY_SEARCH_TTL", 5*time.Minute),
|
|
ScreensaverTTL: duration("MEMBY_SCREENSAVER_TTL", 10*time.Minute),
|
|
SessionTTL: duration("MEMBY_SESSION_CACHE_TTL", 5*time.Minute),
|
|
SessionIdleExpiry: duration("MEMBY_SESSION_IDLE_EXPIRY", 90*24*time.Hour),
|
|
RecommendTTL: duration("MEMBY_RECOMMEND_TTL", 24*time.Hour),
|
|
RecommendTimeout: duration("MEMBY_RECOMMEND_TIMEOUT", 60*time.Second),
|
|
MagicPoolTTL: duration("MEMBY_MAGIC_POOL_TTL", 2*time.Hour),
|
|
RecommendationWeights: strings.TrimSpace(
|
|
os.Getenv("MEMBY_RECOMMENDATION_WEIGHTS"),
|
|
),
|
|
RemoteConfig: remoteConfig,
|
|
|
|
AdminToken: strings.TrimSpace(os.Getenv("MEMBY_ADMIN_TOKEN")),
|
|
AdminUIURL: env("MEMBY_ADMIN_UI_URL", "http://memby-admin:80"),
|
|
PublicURL: strings.TrimRight(strings.TrimSpace(os.Getenv("MEMBY_PUBLIC_URL")), "/"),
|
|
ReleaseDir: env("MEMBY_RELEASE_DIR", "/data/releases"),
|
|
ReleasePublishToken: releasePublishToken,
|
|
SyncInterval: duration("MEMBY_SYNC_INTERVAL", time.Hour),
|
|
SyncTimeout: duration("MEMBY_SYNC_TIMEOUT", 30*time.Minute),
|
|
SyncOnStart: boolean("MEMBY_SYNC_ON_START", false),
|
|
SyncUserID: strings.TrimSpace(os.Getenv("MEMBY_SYNC_USER_ID")),
|
|
SyncAPIKey: strings.TrimSpace(os.Getenv("MEMBY_SYNC_API_KEY")),
|
|
AnalyticsRetention: duration("MEMBY_ANALYTICS_RETENTION", 90*24*time.Hour),
|
|
UpstreamTimeout: duration("MEMBY_UPSTREAM_TIMEOUT", 20*time.Second),
|
|
SlowRequestThreshold: duration("MEMBY_SLOW_REQUEST_THRESHOLD", 500*time.Millisecond),
|
|
EmbyHealthInterval: duration("MEMBY_EMBY_HEALTH_INTERVAL", 60*time.Second),
|
|
SonarrURL: strings.TrimRight(strings.TrimSpace(os.Getenv("MEMBY_SONARR_URL")), "/"),
|
|
SonarrAPIKey: strings.TrimSpace(os.Getenv("MEMBY_SONARR_API_KEY")),
|
|
SonarrTTL: duration("MEMBY_SONARR_TTL", 5*time.Minute),
|
|
SonarrAlertWindow: duration("MEMBY_SONARR_ALERT_WINDOW", 3*time.Hour),
|
|
SonarrWebhookToken: strings.TrimSpace(os.Getenv("MEMBY_SONARR_WEBHOOK_TOKEN")),
|
|
IngestSettleDelay: duration("MEMBY_ARR_INGEST_SETTLE", time.Minute),
|
|
RadarrURL: strings.TrimRight(strings.TrimSpace(os.Getenv("MEMBY_RADARR_URL")), "/"),
|
|
RadarrAPIKey: strings.TrimSpace(os.Getenv("MEMBY_RADARR_API_KEY")),
|
|
RadarrTTL: duration("MEMBY_RADARR_TTL", 5*time.Minute),
|
|
RadarrWebhookToken: strings.TrimSpace(os.Getenv("MEMBY_RADARR_WEBHOOK_TOKEN")),
|
|
RadarrAlertWindow: duration("MEMBY_RADARR_ALERT_WINDOW", 3*time.Hour),
|
|
BazarrURL: strings.TrimRight(strings.TrimSpace(os.Getenv("MEMBY_BAZARR_URL")), "/"),
|
|
BazarrAPIKey: strings.TrimSpace(os.Getenv("MEMBY_BAZARR_API_KEY")),
|
|
BazarrTTL: duration("MEMBY_BAZARR_TTL", 5*time.Minute),
|
|
BazarrTimeout: duration("MEMBY_BAZARR_TIMEOUT", 45*time.Second),
|
|
CreditsEnabled: boolean("MEMBY_CREDITS_ENABLED", false),
|
|
CreditsFFmpeg: strings.TrimSpace(os.Getenv("MEMBY_CREDITS_FFMPEG")),
|
|
CreditsPrefetchEpisodes: integer("MEMBY_CREDITS_PREFETCH_EPISODES", 3),
|
|
CreditsMaxPrefetch: integer("MEMBY_CREDITS_MAX_PREFETCH", 5),
|
|
CreditsQueueLimit: integer("MEMBY_CREDITS_QUEUE_LIMIT", 20),
|
|
TracearrURL: strings.TrimRight(strings.TrimSpace(os.Getenv("MEMBY_TRACEARR_URL")), "/"),
|
|
TracearrAPIKey: strings.TrimSpace(os.Getenv("MEMBY_TRACEARR_API_KEY")),
|
|
TracearrServerID: strings.TrimSpace(os.Getenv("MEMBY_TRACEARR_SERVER_ID")),
|
|
TracearrSyncInterval: duration("MEMBY_TRACEARR_SYNC_INTERVAL", 5*time.Minute),
|
|
TracearrFullInterval: duration("MEMBY_TRACEARR_FULL_INTERVAL", 24*time.Hour),
|
|
ForYouMinRebuildAge: duration("MEMBY_FOR_YOU_MIN_REBUILD_AGE", 24*time.Hour),
|
|
ForYouRefreshInterval: duration("MEMBY_FOR_YOU_REFRESH_INTERVAL", 24*time.Hour),
|
|
ForYouRebuildHour: integer("MEMBY_FOR_YOU_REBUILD_HOUR", 4),
|
|
}
|
|
if c.AnalyticsRetention < 30*24*time.Hour {
|
|
c.AnalyticsRetention = 30 * 24 * time.Hour
|
|
}
|
|
|
|
if c.EmbyURL == "" {
|
|
return c, fmt.Errorf("MEMBY_EMBY_URL is required")
|
|
}
|
|
if c.DatabaseURL == "" {
|
|
return c, fmt.Errorf("MEMBY_DATABASE_URL is required")
|
|
}
|
|
if c.EmbyPublicURL == "" {
|
|
c.EmbyPublicURL = c.EmbyURL
|
|
}
|
|
if c.EmbyMediaURL == "" {
|
|
c.EmbyMediaURL = c.EmbyURL
|
|
}
|
|
if c.ReleasePublishToken != "" && c.PublicURL == "" {
|
|
return c, fmt.Errorf("MEMBY_PUBLIC_URL is required when release publishing is enabled")
|
|
}
|
|
if (c.SonarrURL == "") != (c.SonarrAPIKey == "") {
|
|
return c, fmt.Errorf("MEMBY_SONARR_URL and MEMBY_SONARR_API_KEY must be set together")
|
|
}
|
|
if (c.RadarrURL == "") != (c.RadarrAPIKey == "") {
|
|
return c, fmt.Errorf("MEMBY_RADARR_URL and MEMBY_RADARR_API_KEY must be set together")
|
|
}
|
|
if (c.BazarrURL == "") != (c.BazarrAPIKey == "") {
|
|
return c, fmt.Errorf("MEMBY_BAZARR_URL and MEMBY_BAZARR_API_KEY must be set together")
|
|
}
|
|
if (c.TracearrURL == "") != (c.TracearrAPIKey == "") {
|
|
return c, fmt.Errorf("MEMBY_TRACEARR_URL and MEMBY_TRACEARR_API_KEY must be set together")
|
|
}
|
|
if c.ForYouRebuildHour < 0 || c.ForYouRebuildHour > 23 {
|
|
return c, fmt.Errorf("MEMBY_FOR_YOU_REBUILD_HOUR must be between 0 and 23")
|
|
}
|
|
if c.RecommendationWeights != "" && !json.Valid([]byte(c.RecommendationWeights)) {
|
|
return c, fmt.Errorf("MEMBY_RECOMMENDATION_WEIGHTS must be valid JSON")
|
|
}
|
|
location, err := time.LoadLocation(env("MEMBY_TIMEZONE", "Pacific/Auckland"))
|
|
if err != nil {
|
|
return c, fmt.Errorf("MEMBY_TIMEZONE: %w", err)
|
|
}
|
|
c.SonarrLocation = location
|
|
c.RadarrLocation = location
|
|
return c, nil
|
|
}
|
|
|
|
func env(key, fallback string) string {
|
|
if v := strings.TrimSpace(os.Getenv(key)); v != "" {
|
|
return v
|
|
}
|
|
return fallback
|
|
}
|
|
|
|
// secret reads a Docker/Kubernetes-style file-backed secret when KEY_FILE is set,
|
|
// falling back to KEY for existing non-Compose deployments. The file's contents are
|
|
// never included in an error, and Compose uses only the file form so `docker inspect`
|
|
// cannot reveal the release-publish credential.
|
|
func secret(key string) (string, error) {
|
|
path := strings.TrimSpace(os.Getenv(key + "_FILE"))
|
|
if path == "" {
|
|
return strings.TrimSpace(os.Getenv(key)), nil
|
|
}
|
|
value, err := os.ReadFile(path)
|
|
if err != nil {
|
|
return "", fmt.Errorf("%s_FILE: %w", key, err)
|
|
}
|
|
trimmed := strings.TrimSpace(string(value))
|
|
if trimmed == "" {
|
|
return "", fmt.Errorf("%s_FILE is empty", key)
|
|
}
|
|
return trimmed, nil
|
|
}
|
|
|
|
func boolean(key string, fallback bool) bool {
|
|
raw := strings.TrimSpace(os.Getenv(key))
|
|
if raw == "" {
|
|
return fallback
|
|
}
|
|
value, err := strconv.ParseBool(raw)
|
|
if err != nil {
|
|
return fallback
|
|
}
|
|
return value
|
|
}
|
|
|
|
func duration(key string, fallback time.Duration) time.Duration {
|
|
raw := strings.TrimSpace(os.Getenv(key))
|
|
if raw == "" {
|
|
return fallback
|
|
}
|
|
if d, err := time.ParseDuration(raw); err == nil {
|
|
return d
|
|
}
|
|
// Bare numbers are read as seconds, which is friendlier in a compose file.
|
|
if secs, err := strconv.Atoi(raw); err == nil {
|
|
return time.Duration(secs) * time.Second
|
|
}
|
|
return fallback
|
|
}
|
|
|
|
func integer(key string, fallback int) int {
|
|
raw := strings.TrimSpace(os.Getenv(key))
|
|
if raw == "" {
|
|
return fallback
|
|
}
|
|
value, err := strconv.Atoi(raw)
|
|
if err != nil {
|
|
return fallback
|
|
}
|
|
return value
|
|
}
|