Problem
When Prepared file directory (download.artifact_dir) is blank, the main server writes prepared downloads to /tmp/silo-download-artifacts, a sibling of the transcode directory. The default docker-compose.yml mounts /tmp/silo-transcode but not that sibling, so prepared downloads land in the container's writable layer:
- They are lost whenever the container is recreated, which every image update does. Silo then finds ready artifacts with missing output and requeues them, so each update re-prepares every ready download.
- They grow on Docker's root filesystem instead of under
SILO_DATA_ROOT, and download.artifact_max_bytes defaults to 0 (no limit).
This affects every default Docker install that prepares downloads on the main server. Dedicated transcode nodes are not affected: with the setting blank they write to download-artifacts inside their transcode directory, which the node examples mount.
Found by reading the code and Compose file while auditing the docs for #1635; not reproduced on a running server.
Options
- Mount
${SILO_DATA_ROOT:-/opt/silo}/download-artifacts:/tmp/silo-download-artifacts on the silo service. This is the smallest change and keeps the sibling rule, which exists so the orphaned-transcode sweep can't delete prepared downloads.
- Or set
download.artifact_dir to a mounted path by default in the Compose deployment.
- Either way, consider a non-zero default for
download.artifact_max_bytes, or document that the directory is unbounded.
Technical notes
internal/config/config.go:453 (EffectiveDownloadArtifactDir): blank setting resolves to a silo-download-artifacts sibling of the transcode directory; the comment explains why it must not nest inside it.
docker-compose.yml: the silo service mounts ${SILO_DATA_ROOT:-/opt/silo}/transcode:/tmp/silo-transcode and nothing for the artifact root.
internal/transcodenode/server.go:495: nodes default to downloadprepare.ArtifactDirectoryName inside their transcode directory.
internal/downloads/artifact_repo.go:332 (RecoverMissing): requeues ready artifacts whose output is missing.
internal/config/admin_settings.go:215: download.artifact_max_bytes defaults to "0".
AI disclosure
- Harness: T3 Code (Claude Code agent harness)
- Tool(s): Claude Code, GitHub CLI
- Model(s): claude-opus-5-5
- Involvement: AI-assisted; filed at the maintainer's request
- Adversarial review: n/a
Problem
When Prepared file directory (
download.artifact_dir) is blank, the main server writes prepared downloads to/tmp/silo-download-artifacts, a sibling of the transcode directory. The defaultdocker-compose.ymlmounts/tmp/silo-transcodebut not that sibling, so prepared downloads land in the container's writable layer:SILO_DATA_ROOT, anddownload.artifact_max_bytesdefaults to0(no limit).This affects every default Docker install that prepares downloads on the main server. Dedicated transcode nodes are not affected: with the setting blank they write to
download-artifactsinside their transcode directory, which the node examples mount.Found by reading the code and Compose file while auditing the docs for #1635; not reproduced on a running server.
Options
${SILO_DATA_ROOT:-/opt/silo}/download-artifacts:/tmp/silo-download-artifactson thesiloservice. This is the smallest change and keeps the sibling rule, which exists so the orphaned-transcode sweep can't delete prepared downloads.download.artifact_dirto a mounted path by default in the Compose deployment.download.artifact_max_bytes, or document that the directory is unbounded.Technical notes
internal/config/config.go:453(EffectiveDownloadArtifactDir): blank setting resolves to asilo-download-artifactssibling of the transcode directory; the comment explains why it must not nest inside it.docker-compose.yml: thesiloservice mounts${SILO_DATA_ROOT:-/opt/silo}/transcode:/tmp/silo-transcodeand nothing for the artifact root.internal/transcodenode/server.go:495: nodes default todownloadprepare.ArtifactDirectoryNameinside their transcode directory.internal/downloads/artifact_repo.go:332(RecoverMissing): requeues ready artifacts whose output is missing.internal/config/admin_settings.go:215:download.artifact_max_bytesdefaults to"0".AI disclosure