Initial commit: Null DRM Official

Capture, decrypt, and restream toolkit with compiled-in app modules
(RTE, TG4, BBC), on-device MITM proxy, streamd control plane, and www.
BBC module.yaml is published (clear streams); other module values stay local.
This commit is contained in:
404errordeveloper 2026-10-06 00:25:35 +02:00
commit 2fa8f2435f
121 changed files with 17802 additions and 0 deletions

65
apps/streamd/README.md Normal file
View file

@ -0,0 +1,65 @@
# streamd
Control plane: REST API, SQLite, dashboard and media supervisor. Hosted by the
single binary as `drm serve`.
```text
apps/streamd/
servecmd/ the command body, imported by apps/cli
internal/api HTTP handlers
internal/db SQLite store
internal/ui dashboard (index.html, app.js, app.css)
internal/supervisor downloader + ffmpeg supervision
internal/ws agent heartbeat
```
## Run
```bash
./bin/drm serve --bind 127.0.0.1:8083 --data .cache/streamd --token SECRET
```
Port 8083 by default, to stay clear of anything already on 8080/8081. Media tools
resolve from flags, then env (`NRE_PATH` / `FFMPEG_PATH` / `MP4DECRYPT_PATH`), then
`bin/`, then `PATH` — no machine-specific paths are baked in.
Open `http://HOST:8083/` and put the token in the header box for mutating actions.
## API
| Method | Path | Notes |
|---|---|---|
| GET | `/api/health` | liveness + uptime |
| GET | `/api/apps` | compiled-in app modules, channels, registered rewriters |
| GET | `/api/streams` | list + runtime (the agent polls this) |
| POST | `/api/streams` | create |
| GET/PATCH/DELETE | `/api/streams/:id` | detail / edit / delete |
| POST | `/api/streams/:id/start\|stop\|restart` | desired state |
| POST | `/api/streams/:id/credentials` | `{mpd,key,pssh?,auth?,pid?}`, restarts if enabled |
| POST | `/api/streams/:id/claim` | agent lease (`agent_id`, TTL ~3m) |
| POST | `/api/streams/:id/claim/release` | release lease |
Mutating routes need `Authorization: Bearer TOKEN` (or `X-Streamd-Token`, or
`?token=`). HLS output is served from `--data/www` at `/hls/<name>/index.m3u8`.
## No provider knowledge
The schema has no provider defaults, and the dashboard's app/channel pickers come
from `/api/apps`. Per-stream downloader settings resolve at start time:
```text
stored row -> the stream's app module (app.StreamDefaults) -> neutral defaults
```
The manifest rewriter is a registry lookup on the stream's `rewriter` column, and
HLS is detected from the manifest shape — not from an app or stream name.
## Status
| Area | State |
|---|---|
| serve + SQLite + CRUD UI + claims + credentials | done |
| `/api/apps` + module-driven defaults | done |
| Real downloader/ffmpeg workers + playlist health | partial — least exercised path |
**Full guide: [docs/streamd.md](../../docs/streamd.md)**