The application the design describes: Flask + SQLite, Plex for library data, Tautulli for watch history, report-only. Structure follows the design's seams. providers/ splits MediaProvider from HistoryProvider, because on this network library data and watch data live on different machines and Jellyfin later will have no Tautulli equivalent. scoring.py implements the reclaim score twice - as a SQL expression for the live grid (weights change on every slider drag, so storing it would mean rewriting thousands of rows per drag) and in Python for CSV export and tests, with a property test over 500 generated rows asserting the two agree. rules.py compiles saved views to parameterized SQL through a field/operator whitelist; nothing user-supplied is ever interpolated. Three properties are enforced by test rather than asserted in prose: - Ingest is idempotent. Three consecutive full scans leave every count and every byte total unchanged. A scanner that double-counts produces a report that looks plausible and is wrong. - Keep marks survive Plex reassigning every rating key in the library. They are keyed on content GUID, scoped per library so the Movies and 4K Movies copies of the same film mark independently. - Every config variable the app reads is declared in docker-compose.yml, so a variable set in Portainer can never silently do nothing. Also found and fixed while verifying against a fake Plex+Tautulli pair: executescript() commits the pending transaction, so migrations needed their BEGIN/COMMIT inside the script; replaceChildren() renders null as the literal text "null"; a hash-only URL change does not reload the document, so deep links needed a hashchange listener; and SQLite ROUND rounds half away from zero where Python rounds half to even. 73 tests, no live server required. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GVbG48GAXfCZatcmX123Ra
41 lines
1.6 KiB
Docker
41 lines
1.6 KiB
Docker
# Multi-stage so build deps don't ship in the runtime image.
|
|
FROM python:3.12-slim AS build
|
|
|
|
WORKDIR /build
|
|
COPY requirements.txt .
|
|
RUN pip install --no-cache-dir --prefix=/install -r requirements.txt
|
|
|
|
|
|
FROM python:3.12-slim
|
|
|
|
LABEL org.opencontainers.image.title="MediaShelf" \
|
|
org.opencontainers.image.description="Plex library analytics and reclaim reporting" \
|
|
org.opencontainers.image.source="https://gitlab.hallsworth.ca/yrtria/MediaShelf"
|
|
|
|
COPY --from=build /install /usr/local
|
|
|
|
# Non-root. /data is the only writable path the app needs.
|
|
RUN useradd --create-home --uid 10001 mediashelf \
|
|
&& mkdir -p /data && chown mediashelf:mediashelf /data
|
|
|
|
WORKDIR /app
|
|
COPY --chown=mediashelf:mediashelf mediashelf/ ./mediashelf/
|
|
COPY --chown=mediashelf:mediashelf wsgi.py ./
|
|
|
|
USER mediashelf
|
|
VOLUME ["/data"]
|
|
EXPOSE 8080
|
|
|
|
ENV PYTHONUNBUFFERED=1 \
|
|
PYTHONDONTWRITEBYTECODE=1 \
|
|
DATABASE_PATH=/data/mediashelf.db
|
|
|
|
HEALTHCHECK --interval=60s --timeout=10s --start-period=20s --retries=3 \
|
|
CMD python -c "import urllib.request,sys; sys.exit(0 if urllib.request.urlopen('http://localhost:8080/healthz', timeout=8).status==200 else 1)"
|
|
|
|
# Two workers: enough for one person browsing while a scan runs. The scheduler
|
|
# starts in exactly one of them, guarded by an flock on /data (see §11.4).
|
|
# --preload is deliberately NOT used: it would run the app factory before the
|
|
# fork, so both workers would inherit one already-open SQLite connection.
|
|
CMD ["gunicorn", "--workers", "2", "--threads", "4", "--bind", "0.0.0.0:8080", \
|
|
"--timeout", "120", "--access-logfile", "-", "wsgi:app"]
|