{ ... }: # Prowlarr — indexer manager (usenet + torrent), feeds SABnzbd/MediaManager. # dataDir is left at the module default: a *custom* dataDir makes the # upstream module force-reset it to 0700 root:root on every boot, stomping # DynamicUser's access ("unable to open database file"). Instead bind-mount # the real (migrated-from-ZimaOS) config dir onto the default path, so # DynamicUser+StateDirectory chowns it on first activation like a fresh # install — no manual chown needed. # # Mount onto /var/lib/private/prowlarr, NOT the public /var/lib/prowlarr: # StateDirectory symlinks the public path to .../private/; binding # onto the public path itself blocks systemd's migrate-on-start rename # ("Device or resource busy", exit 238/STATE_DIRECTORY). { services.prowlarr.enable = true; # `nofail` is not optional: without it this bind is RequiredBy local-fs.target, # so an unassembled array drops jupiter into emergency mode — a dead end on a # headless box with root locked. Let this bind fail alone instead. fileSystems."/var/lib/private/prowlarr" = { device = "/mnt/data/AppData/prowlarr/config"; fsType = "none"; options = [ "bind" "nofail" ]; }; # systemd derives RequiresMountsFor only from /var/lib/prowlarr (eMMC) — pin # it to the array too, or prowlarr starts happily and writes state to the OS disk. systemd.services.prowlarr.unitConfig.RequiresMountsFor = [ "/mnt/data" ]; }