align romm shim with jellyfin/navidrome uid pattern (romm_uid/romm_gid)
This commit is contained in:
@@ -11,6 +11,14 @@ romm_restart_policy: "{{ app_restart_policy | default('unless-stopped') }}"
|
||||
# Network configuration
|
||||
romm_http_port: 8080
|
||||
|
||||
# User the romm container runs as. Defaults to app_uid/app_gid (the ansible
|
||||
# connection user, or root under become). Override in your playbook to
|
||||
# align with host user perms on bind-mounted paths (e.g. NFS). Applies to
|
||||
# the romm service only; mariadb manages its own user internally. Also used
|
||||
# as the owner of the app-managed subdirectories.
|
||||
romm_uid: "{{ app_uid }}"
|
||||
romm_gid: "{{ app_gid }}"
|
||||
|
||||
# Volume paths
|
||||
romm_library_path: "{{ app_dir }}/library"
|
||||
romm_assets_path: "{{ app_dir }}/assets"
|
||||
|
||||
@@ -10,13 +10,18 @@ dependencies:
|
||||
app_role_name: romm
|
||||
# romm_library_path is intentionally excluded: it's user-managed
|
||||
# external storage (often on NFS/SMB with pre-existing perms).
|
||||
# mysql_data_path needs uid/gid 999 (mysql user inside the mariadb
|
||||
# container) and mode 0700 (mariadb refuses world/group access).
|
||||
# mysql_data_path is chowned to 999:999 mode 0700 for the mariadb
|
||||
# container's mysql user. App dirs match romm_puid/romm_pgid when set;
|
||||
# otherwise fall back to the base role's app_uid/app_gid.
|
||||
app_subdirectories: >-
|
||||
{{
|
||||
[romm_assets_path, romm_config_path, romm_resources_path,
|
||||
{'path': romm_mysql_data_path, 'owner': 999, 'group': 999, 'mode': '0700'}]
|
||||
+ ([romm_redis_data_path] if romm_redis_data_path else [])
|
||||
[
|
||||
{'path': romm_assets_path, 'owner': romm_uid, 'group': romm_gid},
|
||||
{'path': romm_config_path, 'owner': romm_uid, 'group': romm_gid},
|
||||
{'path': romm_resources_path, 'owner': romm_uid, 'group': romm_gid},
|
||||
{'path': romm_mysql_data_path, 'owner': 999, 'group': 999, 'mode': '0700'},
|
||||
]
|
||||
+ ([{'path': romm_redis_data_path, 'owner': romm_uid, 'group': romm_gid}] if romm_redis_data_path else [])
|
||||
}}
|
||||
app_backup_subdirectories:
|
||||
- "{{ romm_assets_path }}"
|
||||
|
||||
@@ -4,6 +4,7 @@ services:
|
||||
image: "rommapp/romm:{{ romm_container_version }}"
|
||||
container_name: "{{ romm_container_name }}"
|
||||
restart: "{{ romm_restart_policy }}"
|
||||
user: "{{ romm_uid }}:{{ romm_gid }}"
|
||||
env_file:
|
||||
- .env
|
||||
volumes:
|
||||
|
||||
Reference in New Issue
Block a user