## ## Configuration of the on-demand browser container. ## ## Sourced by /etc/quadlets/seedbox/seedbox-waypipe.sh (as root) and by ## /etc/profile.d/seedbox.sh, so keep it to plain shell assignments. ## ## Every setting uses the ${VAR:-default} form so that an environment variable ## still wins over the file, which makes one-off overrides easy: ## BROWSER_PODMAN_OPTS=--security-opt=seccomp=unconfined seedbox-browser ... ## ## It is owned by root:root on purpose (see the seedbox Makefile): the shim ## sources it with root privileges, so it must not be writable by the seedbox ## user the browser runs as. ## # Container image, rebuilt every night by librewolf-build.timer. BROWSER_IMAGE="${BROWSER_IMAGE:-localhost/librewolf:latest}" # The browser runs as the unprivileged seedbox user, like the rest of the stack. # Changing these means rebuilding the image: the Containerfile creates # /run/user/ (the browser's XDG_RUNTIME_DIR) with matching ownership. BROWSER_UID="${BROWSER_UID:-10017}" BROWSER_GID="${BROWSER_GID:-10000}" # Persistent browser profile: bookmarks, cookies, extension state. # On the production seedbox, point this at the SSD virtiofs mount instead: # BROWSER_PROFILE_DIR=/var/lib/virtiofs/ssd/librewolf BROWSER_PROFILE_DIR="${BROWSER_PROFILE_DIR:-/var/lib/quadlets/seedbox/librewolf}" # Where downloads land. On the production seedbox, the import directory the # *arr stack already watches is the obvious candidate: # BROWSER_DOWNLOAD_DIR=/var/lib/virtiofs/hdd/import BROWSER_DOWNLOAD_DIR="${BROWSER_DOWNLOAD_DIR:-/var/lib/quadlets/seedbox/downloads}" # Firefox-family browsers are multi-process and need a large /dev/shm. BROWSER_SHM_SIZE="${BROWSER_SHM_SIZE:-1g}" # --no-gpu: there is no GPU in this VM, so block wayland-drm and linux-dmabuf # instead of letting waypipe negotiate them and fail. # # These are only added when the client has not passed them already: "waypipe # ssh" forwards several of its own options to the server side, and a repeated # flag is a hard error ("cannot be used multiple times"). BROWSER_WAYPIPE_OPTS="${BROWSER_WAYPIPE_OPTS:---no-gpu}" # Escape hatch for extra podman arguments, e.g. if the browser's own sandbox # ends up needing a looser seccomp profile: # BROWSER_PODMAN_OPTS="--security-opt seccomp=unconfined" BROWSER_PODMAN_OPTS="${BROWSER_PODMAN_OPTS:-}"