A web UI that imports FLAC music from ZIP archives — extracts, tags with beets, renames files, and moves to a configured output directory.
Start the container:
docker run -p 8080:8080 \
-v /path/to/music:/music \
-v /path/to/downloads:/downloads \
-e OUTPUT_BASE=/music \
-e OUTPUT_FORMAT="%albumartist%/%year% - %albumname%"
Open http://localhost:8080, upload a .zip with FLAC files.
| Variable | Default | Description |
|---|---|---|
OUTPUT_BASE | /music | Root directory for organized output |
OUTPUT_FORMAT | %albumartist%/%year% - %albumname% | Path template; variables: %albumartist%, %year%, %albumname% |
AUTH_PASSWORD | (empty) | Optional shared password for the login form |
LOCAL_LOGIN | true | Set to false to disable local password login entirely (hides the form, rejects the login POST, and disables password auth on /import) |
SESSION_SECRET | change-me-in-production | Secret used to sign session cookies — must be changed |
OIDC_ISSUER | (empty) | OpenID Connect issuer URL (enables OIDC login) |
OIDC_CLIENT_ID | (empty) | OIDC client id |
OIDC_CLIENT_SECRET | (empty) | OIDC client secret |
OIDC_PROVIDER_NAME | OIDC | Display name of your identity provider, shown on the SSO login button ("Login with <name>") |
EXTERNAL_URL | (empty) | Public URL the app is served at (e.g. https://musicimport.example.com). The OIDC callback URI is derived from this as EXTERNAL_URL + /auth/callback; also used to detect HTTPS for the session cookie |
FORWARDED_ALLOW_IPS | 127.0.0.1 | Comma-separated IPs of trusted reverse proxies whose X-Forwarded-* headers are accepted |
The app supports OpenID Connect login (e.g. Keycloak, Authentik, Authelia, Google, GitHub). When OIDC is enabled, users click "Login with SSO" and are redirected to your IdP.
The OIDC_ISSUER is the base OIDC endpoint of your provider (e.g. https://auth.sfsk.nl/oidc or https://idp.example.com/realms/my-realm). The app automatically discovers the authorization, token, and userinfo endpoints by requesting OIDC_ISSUER + /.well-known/openid-configuration.
At the provider side, create a new OIDC/OAuth2 application and set:
https://musicimport.example.com/auth/callback — the public URL of your app plus /auth/callback. It must match the derived callback URI exactly (see below).openid email profileNote the issuer/base OIDC URL, the client ID, and the client secret the provider gives you.
docker run -p 8080:8080 \
-v /path/to/music:/music \
-v /path/to/downloads:/downloads \
-e OUTPUT_BASE=/music \
-e EXTERNAL_URL=https://musicimport.example.com \
-e OIDC_ISSUER=https://idp.example.com/oidc \
-e OIDC_CLIENT_ID=music-import \
-e OIDC_CLIENT_SECRET=your-client-secret \
-e SESSION_SECRET=a-long-random-string
The callback (redirect) URI is always https://<your-public-host>/auth/callback, i.e. EXTERNAL_URL + "/auth/callback". It is derived from EXTERNAL_URL — there is no separate setting. So if EXTERNAL_URL=https://musicimport.example.com, the callback is https://musicimport.example.com/auth/callback.
The value registered in the IdP must match exactly (scheme, host, port, and path) what the app sends, otherwise the provider rejects the redirect.
When the app runs behind a reverse proxy (nginx/Traefik) terminating TLS:
EXTERNAL_URL to the public https:// URL so the callback URI and session cookie scheme are correct.FORWARDED_ALLOW_IPS to the proxy's IP address so uvicorn trusts its X-Forwarded-Proto / X-Forwarded-For headers. Without this the app sees the internal http scheme and the proxy's IP instead of the public URL, and OIDC login fails.FORWARDED_ALLOW_IPS can stay at its default.EXTERNAL_URL + /auth/callback. Compare them exactly.http instead of https: EXTERNAL_URL is not set, or FORWARDED_ALLOW_IPS doesn't include the proxy, so uvicorn ignores the X-Forwarded-Proto header./ unauthenticated: check the session cookie SESSION_SECRET is stable across restarts.python app.py /path/to/file.zip
Content type
Image
Digest
sha256:94b21e508…
Size
197.7 MB
Last updated
about 1 month ago
docker pull spinkever/music-import