Downloaders

The media stack uses two download clients: qBittorrent for torrents and SABnzbd for Usenet. Both are driven by Sonarr and Radarr, run on worker-07 (wibrow.dev/compute: "true"), and keep their config on a PVC from the pvc component, backed up hourly by kopiur.

qBittorrent

qBittorrent is the primary torrent client, handling downloads triggered by Sonarr, Radarr, and Autobrr.

Deployment Details

SettingValue
Imageghcr.io/home-operations/qbittorrent
Port8080 (WebUI)
Gatewayenvoy-internal
URLqbittorrent.wibrow.dev

Configuration

Key environment variables
env:
  UMASK: "022"
  QBT_WEBUI_PORT: 8080

Storage

MountSourcePurpose
/configPVC qbittorrent-configqBittorrent configuration and database
/data/nas-media/downloads/qbittorrentNFS data:/volume1/mediaDownload directory (subpath)
Download path configuration
persistence:
  config:
    existingClaim: qbittorrent-config
    advancedMounts:
      qbittorrent:
        app:
          - path: /config
  downloads:
    type: nfs
    server: data
    path: /volume1/media
    globalMounts:
      - path: /data/nas-media
        subPath: downloads/qbittorrent

Security Context

qBittorrent runs with a hardened security context:

yaml
securityContext:
  runAsUser: 2000
  runAsGroup: 2000
  runAsNonRoot: true
  allowPrivilegeEscalation: false
  readOnlyRootFilesystem: true
  capabilities:
    drop:
      - ALL

Resources

yaml
resources:
  requests:
    cpu: 100m
    memory: 128Mi
  limits:
    memory: 8192Mi

SABnzbd

SABnzbd is the Usenet download client, providing an alternative download path to torrents for Sonarr and Radarr.

Deployment Details

SettingValue
Imageghcr.io/home-operations/sabnzbd
Port8080 (WebUI)
Gatewayenvoy-internal
URLsabnzbd.wibrow.dev
Node Selectorkubernetes.io/arch: amd64, wibrow.dev/compute: "true"

Configuration

Key environment variables
env:
  SABNZBD__PORT: 8080
  SABNZBD__HOST_WHITELIST_ENTRIES: >-
    sabnzbd,
    sabnzbd.downloads,
    sabnzbd.downloads.svc,
    sabnzbd.downloads.svc.cluster,
    sabnzbd.downloads.svc.cluster.local,
    sabnzbd.wibrow.dev

Storage

MountSourcePurpose
/configPVC sabnzbd-configSABnzbd configuration
/data/nas-mediaNFS data:/volume1/mediaMedia library (for post-processing)
/downloadsPVC sabnzbd-downloads (50Gi, openebs-hostpath-fast)Active download staging area
/tmpemptyDirTemporary files
Storage mounts
persistence:
  config:
    existingClaim: sabnzbd-config
  media:
    type: nfs
    server: data
    path: /volume1/media
    globalMounts:
      - path: /data/nas-media
  downloads:
    existingClaim: sabnzbd-downloads

Security Context

SABnzbd runs as UID/GID 2000 with a read-only root filesystem and all capabilities dropped.


Integration with Arr Apps

Both download clients are configured as "Download Clients" within Sonarr and Radarr. The typical flow:

  1. Sonarr/Radarr find a release on an indexer (managed by Prowlarr)
  2. The *arr app sends the .torrent or .nzb to qBittorrent or SABnzbd
  3. The download client fetches the content to the NAS
  4. Sonarr/Radarr detect the completed download and import it into the library
sequenceDiagram
    participant S as Sonarr / Radarr
    participant P as Prowlarr
    participant Q as qBittorrent / SABnzbd
    participant N as Synology NAS

    S->>P: Search indexers
    P-->>S: Return results
    S->>Q: Send download request
    Q->>N: Download to /downloads/
    Q-->>S: Notify completion
    S->>N: Import & rename to /library/