11 Commits

Author SHA1 Message Date
benvin f150d915f5 Merge pull request 'Repin SSO plugin to unkin fork 5.0.0.0' (#14) from benvin/sso-fork-repin into main
ci/woodpecker/tag/docker Pipeline was successful
Reviewed-on: #14
2026-09-20 00:53:33 +10:00
unkin-agent b43e10f752 Repin SSO plugin to unkin fork 5.0.0.0
ci/woodpecker/pr/build Pipeline was successful
2026-09-20 00:02:22 +10:00
benvin c4d4dd75a7 Merge pull request 'Repin UPSTREAM_REF to jellyfin-ha-src main' (#13) from benvin/jellyfin-v0.3.2 into main
ci/woodpecker/tag/docker Pipeline was successful
Reviewed-on: #13
2026-09-13 21:06:33 +10:00
unkin-agent 521ef065ca Repin UPSTREAM_REF to jellyfin-ha-src main
ci/woodpecker/pr/build Pipeline was successful
Picks up cross-replica auth read-through, bare Jellyfin__ env config,
the min(uuid) anti-join fix for browse/search/Recently Added, and
scan-leader gating tied to Redis configuration.
2026-09-13 20:25:42 +10:00
benvin e103b57e97 Merge pull request 'fix: make plugin sync safe for concurrent replica starts' (#12) from benvin/fix-plugin-sync-race into main
Reviewed-on: #12
2026-09-13 18:57:11 +10:00
unkin-agent e0a195179b fix: make plugin sync safe for concurrent replica starts
ci/woodpecker/pr/build Pipeline was successful
Two replicas starting together on the shared /config volume race the
unconditional rm+cp, so one dies with a permission error or a plugin
UnauthorizedAccessException. Skip the sync once the correct version
is already present, stage new/changed versions and move them into
place with an atomic rename, and treat a lost rename race or an
already-removed stale version as success rather than failure.
2026-09-13 18:49:52 +10:00
benvin 64b6c01e91 Merge pull request 'build: repin UPSTREAM_REF to fixed PostgreSQL upgrade path' (#10) from benvin/jellyfin-v0.3.1 into main
ci/woodpecker/tag/docker Pipeline was successful
Reviewed-on: #10
2026-09-12 18:17:41 +10:00
unkin-agent c8960dbe82 build: repin UPSTREAM_REF to fixed PostgreSQL upgrade path
ci/woodpecker/pr/build Pipeline was successful
v0.3.0 shipped a regenerated initial migration that broke upgrades
on existing Postgres databases. Pin the fork commit restoring the
baseline plus forward migrations and the EncoderPreset fallback.
2026-09-12 18:09:24 +10:00
benvin 8631c39979 Merge pull request 'Track Jellyfin v12.0' (#9) from benvin/jellyfin-v12 into main
ci/woodpecker/tag/docker Pipeline was successful
Reviewed-on: #9
2026-09-12 13:20:54 +10:00
unkin-agent f7ea7675cb build: repin UPSTREAM_REF to merged v12.0 source
ci/woodpecker/pr/build Pipeline was successful
2026-09-12 12:51:45 +10:00
unkin-agent 2924cbb63d build: track jellyfin v12.0
ci/woodpecker/pr/build Pipeline was successful
- pin UPSTREAM_REF to the v12.0 rebase commit
- move publish to dotnet SDK 10.0 and the runtime to aspnet:10.0
- pin jellyfin-web to 12.0+deb12
- bake LDAP Authentication 24.0.0.0 (targetAbi 12.0.0.0)
- build PR images with the CA-baked buildx plugin
2026-09-12 01:27:48 +10:00
6 changed files with 76 additions and 36 deletions
+2 -2
View File
@@ -5,7 +5,7 @@ steps:
# Clone the pinned upstream jellyfin-ha source and publish the .NET server
# into ./publish-output (consumed by Dockerfile.runtime).
- name: publish
image: mcr.microsoft.com/dotnet/sdk:9.0
image: mcr.microsoft.com/dotnet/sdk:10.0
commands:
- |
REF=$$(cat UPSTREAM_REF)
@@ -26,7 +26,7 @@ steps:
# Validate the runtime image builds (no push on PRs).
- name: docker-build
image: woodpeckerci/plugin-docker-buildx
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/plugin-docker-buildx:latest
settings:
repo: artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha
dockerfile: Dockerfile.runtime
+1 -1
View File
@@ -5,7 +5,7 @@ when:
steps:
# Same publish step as the PR pipeline: clone pinned upstream + dotnet publish.
- name: publish
image: mcr.microsoft.com/dotnet/sdk:9.0
image: mcr.microsoft.com/dotnet/sdk:10.0
commands:
- |
REF=$$(cat UPSTREAM_REF)
+21 -20
View File
@@ -18,48 +18,49 @@ RUN apt-get update \
&& echo "deb [arch=amd64 signed-by=/usr/share/keyrings/jellyfin.gpg] https://repo.jellyfin.org/debian bookworm main" \
> /etc/apt/sources.list.d/jellyfin.list \
&& apt-get update \
&& apt-get install -y --no-install-recommends "jellyfin-web=10.11.6+deb12" \
&& apt-get install -y --no-install-recommends "jellyfin-web=12.0+deb12" \
&& rm -rf /var/lib/apt/lists/*
# ── Plugin stage ──────────────────────────────────────────────────────────────
# Download and verify the auth plugins, unpacked into versioned dirs baked into
# the image and synced into /config/plugins at start (docker-entrypoint.sh).
# Versions are the newest each plugin publishes whose targetAbi <= the pinned
# Jellyfin server version (10.11.6):
# LDAP Authentication 22.0.0.0 targetAbi 10.11.2.0 (v23 needs 10.11.9)
# SSO Authentication 4.0.0.4 targetAbi 10.11.0.0
# sha256 pins match each release's published .sha256 asset for reproducibility.
# Jellyfin server version (12.0.0):
# LDAP Authentication 24.0.0.0 targetAbi 12.0.0.0
# SSO Authentication 5.0.0.0 targetAbi 12.0.0.0
# sha256 pins make each fetch reproducible.
FROM --platform=linux/amd64 debian:bookworm-slim AS plugins
RUN apt-get update \
&& apt-get install -y --no-install-recommends curl ca-certificates unzip \
&& rm -rf /var/lib/apt/lists/*
ARG LDAP_URL=http://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/jellyfin/files/plugin/ldap-authentication/ldap-authentication_22.0.0.0.zip
ARG LDAP_SHA256=c2386c001be439c9946280a02d62610f29e325d4094e83bd31221de3f7aa20ae
# LDAP is served through artifactapi remote. SSO is served through the artifactapi
# github proxy, which the CI build network can reach (github is not directly reachable).
# SHA256 pins match each release's published asset for reproducibility and integrity.
ARG SSO_URL=http://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/9p4/jellyfin-plugin-sso/releases/download/v4.0.0.4/sso-authentication_4.0.0.4.zip
ARG SSO_SHA256=c09f16ba31059a434ddd7f811e4f9608d4b4c4514cc80a5bf1ca33bee61e1107
ARG LDAP_URL=http://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/jellyfin/files/plugin/ldap-authentication/ldap-authentication_24.0.0.0.zip
ARG LDAP_SHA256=3be1f9d6a6ce9ea375e556dd30136d178a8dbe35cbe866d30d3451dc3ff7e804
# Both are served through artifactapi remotes over http: this stage's base image
# trusts only public CAs and artifactapi presents an internal-CA certificate, so
# https here fails to verify. The sha256 pins below supply the integrity guarantee.
# SSO is the in-house unkin fork (valkey-backed OAuth state, shared across replicas).
ARG SSO_URL=http://artifactapi.k8s.syd1.au.unkin.net/api/v2/remotes/jellyfin-plugins/files/unkin/jellyfin-plugin-sso/5.0.0.0/sso-authentication_5.0.0.0.zip
ARG SSO_SHA256=7e5f09cc4c81dce35edca650d74ed0680f425ca65c6221bb75456de9b8557e14
WORKDIR /plugins
RUN set -eu; \
curl -fsSL "$LDAP_URL" -o ldap.zip; \
echo "$LDAP_SHA256 ldap.zip" | sha256sum -c -; \
mkdir -p "LDAP Authentication_22.0.0.0"; \
unzip -oq ldap.zip -d "LDAP Authentication_22.0.0.0"; \
mkdir -p "LDAP Authentication_24.0.0.0"; \
unzip -oq ldap.zip -d "LDAP Authentication_24.0.0.0"; \
curl -fsSL "$SSO_URL" -o sso.zip; \
echo "$SSO_SHA256 sso.zip" | sha256sum -c -; \
mkdir -p "SSO Authentication_4.0.0.4"; \
unzip -oq sso.zip -d "SSO Authentication_4.0.0.4"; \
mkdir -p "SSO Authentication_5.0.0.0"; \
unzip -oq sso.zip -d "SSO Authentication_5.0.0.0"; \
rm -f ldap.zip sso.zip
# ── Runtime stage ─────────────────────────────────────────────────────────────
# .NET 9 runtime: matches the SDK 9.0 publish step (framework-dependent), so the
# app's required Microsoft.NETCore.App 9.0 is present. Keep in lockstep with the
# `mcr.microsoft.com/dotnet/sdk` major in .woodpecker/*.yaml and the Makefile.
FROM --platform=linux/amd64 mcr.microsoft.com/dotnet/aspnet:9.0
# .NET 10 runtime: matches the SDK 10.0 publish step (framework-dependent) and the
# fork's net10.0 TFM, so the app's required Microsoft.NETCore.App 10.0 is present.
# Keep in lockstep with the `mcr.microsoft.com/dotnet/sdk` major in .woodpecker/*.yaml.
FROM --platform=linux/amd64 mcr.microsoft.com/dotnet/aspnet:10.0
# FFmpeg and the native deps required by SkiaSharp and fontconfig.
RUN apt-get update \
+3 -3
View File
@@ -4,12 +4,12 @@ Build-orchestration repo for [ZoltyMat/jellyfin-ha](https://github.com/ZoltyMat/
that adds distributed, Redis-backed transcoding for multi-pod Kubernetes (lease-aware cleanup, HA session
takeover, optional PostgreSQL).
This repo does **not** vendor the fork's source. It pins an upstream commit, builds the .NET 9 server, and
This repo does **not** vendor the fork's source. It pins an upstream commit, builds the .NET 10 server, and
produces a runtime container image pushed to the Gitea registry.
## What it produces
`artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha:<tag>` — an `mcr.microsoft.com/dotnet/aspnet:9.0` based image with ffmpeg and
`artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha:<tag>` — an `mcr.microsoft.com/dotnet/aspnet:10.0` based image with ffmpeg and
the prebuilt `jellyfin-web` client, running the published `jellyfin-ha` server.
## Layout
@@ -34,7 +34,7 @@ the prebuilt `jellyfin-web` client, running the published `jellyfin-ha` server.
make build # clones pinned upstream, dotnet publish, docker build
```
Requires the .NET 9 SDK and Docker. `make publish` runs just the clone + publish into `./publish-output`.
Requires the .NET 10 SDK and Docker. `make publish` runs just the clone + publish into `./publish-output`.
## Deployment
+1 -1
View File
@@ -1 +1 @@
2e1e445e470c2f2c1520f66678a73faa226c2058
ec581b5e5f156edb862d01f4bd07d9ba51903ed6
+48 -9
View File
@@ -1,24 +1,63 @@
#!/bin/sh
# Sync image-baked plugins into the /config (datadir) plugins directory on every
# start. /config is a PVC that overlays the image, so plugins baked into the
# image are invisible until copied in here. Removing any existing versioned dir
# of the same plugin first lets the image version win across restarts/downgrades.
# Sync image-baked plugins into the /config (datadir) plugins directory on
# start. /config is an RWX volume shared across replicas, so plugins baked
# into the image are invisible until copied in here -- and this must be safe
# when several replicas start (or restart) at the same instant:
# - skip entirely once the correct version is already in place, so the
# steady state (almost every start) never touches the shared volume;
# - install a new/changed version via copy-to-staging + atomic rename, so
# no reader (another replica, or this container's own jellyfin process)
# ever observes a partially-written plugin directory. A replica that
# loses the rename race just discards its own copy -- that's success,
# not an error;
# - drop stale, differently-versioned copies of the same plugin afterwards
# so they don't shadow the current one. Best-effort: another replica may
# already be doing, or have finished, the same cleanup.
# Deliberately no locking: a lock held by a replica that dies mid-sync would
# wedge every future start on this volume, which is worse than the race it
# would prevent.
set -eu
BAKED_DIR=/usr/share/jellyfin/plugins-baked
PLUGIN_DIR=/config/plugins
STAGING_DIR="$PLUGIN_DIR/.sync-tmp"
REPLICA=$(hostname)
if [ -d "$BAKED_DIR" ]; then
mkdir -p "$PLUGIN_DIR"
mkdir -p "$PLUGIN_DIR" "$STAGING_DIR"
for src in "$BAKED_DIR"/*; do
[ -d "$src" ] || continue
name=$(basename "$src") # e.g. "LDAP Authentication_22.0.0.0"
name=$(basename "$src") # e.g. "LDAP Authentication_24.0.0.0"
base=${name%_*} # plugin name without the trailing _<version>
target="$PLUGIN_DIR/$name"
if [ ! -d "$target" ]; then
# Build the new version privately (keyed by this replica's own
# hostname, so concurrent replicas never share a staging path), then
# move it into place in one atomic rename. mv -T fails with
# "Directory not empty" if another replica's rename already won --
# that's fine, our copy just becomes garbage we discard.
staging="$STAGING_DIR/$REPLICA.$name"
rm -rf "$staging"
cp -a "$src" "$staging"
if mv_err=$(mv -T "$staging" "$target" 2>&1); then
:
elif [ -d "$target" ]; then
rm -rf "$staging"
else
echo "docker-entrypoint: failed to install plugin $name: $mv_err" >&2
exit 1
fi
fi
# Remove any other version of this plugin so it can't shadow the one
# above. Another replica may be racing the same cleanup, or have already
# finished it -- an entry that's already gone is success, not an error.
for existing in "$PLUGIN_DIR/$base"_*; do
[ -e "$existing" ] && rm -rf "$existing"
[ -e "$existing" ] || continue
[ "$existing" = "$target" ] && continue
rm -rf "$existing" 2>/dev/null || true
done
rm -rf "$PLUGIN_DIR/$name"
cp -a "$src" "$PLUGIN_DIR/$name"
done
fi