Commit Graph
100 Commits
Author SHA1 Message Date
CanbiZ (MickLesk) 556b9c4653 pocketbase-bot: accept the var_ names and two missing fields (#17305)
* pocketbase-bot: accept the var_ names and two missing fields

cpu, ram, hdd, os and version were already reachable, but only under
the PocketBase names. People type what the ct scripts call them, so
"/pocketbase <slug> var_ram=4096" was rejected as an unknown field
while "ram=4096" worked. The bot already carried the mapping as
RESOURCE_TO_CT_VAR, for display only.

Normalise the keys in parseKVPairs, so both the field=value path and
the method path accept them, along with disk and memory as the other
two names people reach for. Matching is case-insensitive.

pin_reason and last_update_commit exist on the record and are worth
editing, but were not in ALLOWED_FIELDS. slug, script_created and
script_updated stay out: the first is the key the command looks the
record up by, the other two belong to the timestamp workflow. notes and
install_methods keep their own subcommands.

* pocketbase-bot: write the sync PR against the PR template

The sync PR body had its own Summary and Source headings, so the
autolabeler found none of the template checkboxes it looks for and the
PR came out with nothing but "needs triage". It also never referenced
the issue the command came from.

Write the body the way the template expects, with the Website update
box ticked, which is what a PocketBase sync is. Tested thoroughly stays
unticked and Tested on says not tested, because nothing here was run;
close-invalid-pr-template skips bot authors, so that costs nothing.

Reference the triggering number as Fixes when the command came from an
issue and as a plain mention when it came from a PR comment, where
Fixes would point the PR at itself. issue_comment carries both under
github.event.issue, so the new IS_PR_COMMENT tells them apart.

* ci: stop the .app header PR being closed as a new script

allowedBots carried "community-scripts-pr-app" but not the
"[bot]"-suffixed name GitHub actually reports, and the check is an exact
match, so the exemption never applied to it. push-app-to-main is listed
both ways; this one was not. PR #17304 was closed as an untested new
script submission because of it.

generate-app-headers.sh empties ct/headers, tools/headers and
vm/headers and writes them again, so every run reports those files as
added. That is what the autolabeler's new-script rule looks for, and
the vm rule matched vm/headers too. Exclude the header directories from
both, and skip them in the close workflow's own added-file fallback, so
the label cannot come back by another route.

Checked against minimatch with the shipped config: header files get
neither label, ct/*.sh, install/*.sh and vm/*.sh still get theirs.

* pocketbase-bot: label the sync PR as a bugfix

The sync corrects CT defaults that no longer match the PocketBase
record, so bugfix describes it better than website update, which is
meant for metadata changes on the site itself.
2026-09-16 13:27:27 +02:00
CanbiZ (MickLesk) b4684b2faf Frigate: Bump to 0.18.0 (#17273)
* frigate: move to 0.18.0

Bump the pinned release and follow the four build changes that matter
outside of Docker.

ffmpeg: 0.18 ships 8.0 as the default and keeps 7.0 and 5.0 alongside
it, so /etc/frigate.env has to name all three or the s6 run script
resolves a version that install_deps.sh never downloaded.

go2rtc: pin to v1.9.14, the version the Dockerfile fetches. "latest"
happened to work but shipped whatever AlexxIT had tagged that day
rather than the build Frigate was tested against.

OpenVINO: requirements-ov.txt dropped tensorflow and openvino-dev, and
build_ov_model.py no longer uses the Model Optimizer. omz_tools is
therefore gone, which left the first two branches of the labelmap
lookup dead; download coco_91cl_bkgr.txt the way the Dockerfile does.

Intel media driver: 0.18 builds intel-media-va-driver-non-free from
source for Battlemage, because the prebuilt noble/trixie packages need
a glibc that bookworm does not have. Run it before install_deps.sh, as
the deps-rootfs stage does, and drop the jammy repo the build adds so
the later trixie pull for libva2 is not resolved against it.

The remaining build scripts and requirement files changed too, but
those come from the checked-out tree and follow the version bump on
their own.

* frigate: stop the detector config from replacing the base config

The install wrote a config with mqtt, cameras, auth and detect, then the
detector branch wrote the file again instead of adding to it. Both
branches used a single redirect, so everything above them was discarded
and the result had neither mqtt nor cameras. frigate/config/config.py
declares both as Field() without a default, in 0.17.2 as well as in
0.18.0, so Frigate rejected the file and came up in safe mode:

  mqtt - Field required
  cameras - Field required

Move hwaccel_args into the base block, since both branches set it, and
append the detector and model sections instead of overwriting.

Checked by generating both branches and parsing the result: the OpenVINO
path yields auth, cameras, detect, detectors, ffmpeg, model, mqtt, the
CPU path the same without detectors, and the test camera survives in
both.

* frigate: write the config in one place

Only the detector and model section depends on the CPU check, but the
file was assembled in three heredocs writing to the same path. That
shape is what produced the safe-mode config: both branches used a plain
redirect and discarded everything above them.

Pick the variable part into DETECTOR_CONFIG first and write the file
once, so the layout is visible in one block and no branch can replace
what came before it.

Output is unchanged, verified by generating both branches from the
previous commit and from this one and diffing: byte-identical.

* Update default RAM and disk values in frigate.sh
2026-09-16 12:01:52 +02:00
CanbiZ (MickLesk) 8050ec7af1 navidrome: repair root-owned data folders left by 0.61.x (#17275)
Navidrome 0.61.x created cache, artwork and plugins under the data
folder whenever any navidrome command ran, including the ones the deb
postinstall runs as root. 0.62 stopped creating them that way but never
corrected the owner, so a container that passed through 0.61.x carries a
root-owned artwork directory. 0.64.0 is the first release to write into
it and fails with

  writing image store: mkdir /var/lib/navidrome/artwork/hashed:
  permission denied

which breaks newly resolved album covers and every playlist cover, since
those are composites.

Repair the three directories the same way navidrome/navidrome#6143 does:
the entries themselves only, since they were created empty, real
directories owned by root only, and chown -h, because the navidrome user
owns the data folder and could otherwise plant a symlink.

The trailing || true is not in the upstream copy and is needed here.
Their postinstall runs without set -e, while update_script runs under
catch_errors, which sets -Ee with an ERR trap. find exits 1 as soon as
one starting point is missing, so on a container without a plugins
directory the update would abort.

Fixes the report in #17247, confirmed there by the reporter's stat and
dpkg log: artwork is root-owned and dated to their 0.60.3 -> 0.61.1
upgrade.
2026-09-16 12:01:42 +02:00
CanbiZ (MickLesk) b17e8e5abf Refactor: HomeAssistant-OS (core / improve functions / performance) (#17281)
* HomeAssistant-OS (VM): Refactor for improved readability

Refactor script to improve readability and maintainability. Updated function calls and variable assignments for better clarity.

* Modify author line in haos-vm.sh

Updated author information in the script header.

* Refactor Home Assistant OS version selection and caching

Refactor advanced settings dialog for Home Assistant OS version selection and simplify image caching logic.
2026-09-16 12:01:34 +02:00
CanbiZ (MickLesk) f5d336cfed tor-snowflake: read the Go version from the module root (#17276)
* tor-snowflake: read the Go version from the module root

Snowflake is a single Go module with go.mod at the repository root, not
under proxy/. The install read /opt/tor-snowflake/proxy/go.mod, which
has never existed, so grep failed and the version came out empty. Go
was then fetched from

  https://go.dev/dl/go.linux-amd64.tar.gz

with no version in the name, and the install aborted at that download.

Read the directive with a single awk instead of grep piped into awk.
The pipeline tripped catch_errors, which sets -Ee with pipefail and an
ERR trap, the moment the file was missing; that is the "exit code 2
while executing command awk" line that preceded the download failure.

Fall back to latest when the file cannot be read, so a future upstream
move of go.mod costs a Go version that is newer than the one pinned
rather than a failed build. setup_go already resolves latest, and also
resolves a bare major.minor to its newest patch, so a go directive
without a patch level stays fine.

Verified against v2.14.1: go.mod sits at the root and declares go
1.24.0, and the awk yields 1.24.0 from it and latest from a missing
file without tripping the ERR trap.

* Refactor GO_VERSION extraction in tor-snowflake.sh

Updated the method of extracting GO_VERSION from go.mod and set a default value if not found.
2026-09-16 11:59:19 +02:00
CanbiZ (MickLesk) 79a320fc3a Refactor: TrueNAS VM (core / improve functions / performance) (#17277)
* Refactor: TrueNAS VM (core / improve functions / performance)

* Boot TrueNAS from sata0, the disk it actually installs to

The boot order named scsi0, which never exists: the system disk is
sata0, and imported passthrough disks start at scsi1 because SCSI_NR is
pre-incremented. So the order always fell through to ide2 and the
installer came back up after every reboot.

* Fix URL in truenas-vm.sh script
2026-09-16 11:59:11 +02:00
CanbiZ (MickLesk) 8b01d1c302 docmost: stop corepack asking for confirmation during the build (#17282)
Docmost pins its package manager, so running pnpm goes through corepack,
which asks before fetching the pinned version:

  Corepack is about to download .../pnpm-11.25.0.tgz
  ? Do you want to continue? [Y/n]

The pnpm calls run under $STD, so with verbose off the question is
never shown and the update sits on "Configuring Docmost" waiting for an
answer nobody can see. With verbose on the same update completes,
because the prompt is visible and gets answered, which is exactly what
the reporter observed.

Set COREPACK_ENABLE_DOWNLOAD_PROMPT=0 before the pnpm calls in both the
install and the update, the way fifteen other ct scripts and ten
install scripts already do.
2026-09-16 11:59:00 +02:00
CanbiZ (MickLesk) fbea9c04c3 monitor-all: decide on flag values, not on key presence (#17261) 2026-09-15 09:16:12 +02:00
CanbiZ (MickLesk) be0a8c3467 Add --no-sync to Paperless uv run services (#17210) 2026-09-12 22:10:47 +02:00
CanbiZ (MickLesk) 764e4232ba Docker VM: Feature Bump - Refactor script for improved functionality (#17216) 2026-09-12 22:10:00 +02:00
CanbiZ (MickLesk) 0a48435ef9 poznote: serve from src/public docroot (#17187) 2026-09-12 12:01:26 +02:00
CanbiZ (MickLesk) 24e006cd81 calibre-web: use calibreweb release identifier to avoid version file collision (#17186) 2026-09-12 08:31:29 +02:00
MickLesk 10ab064f26 formatting fix issue report 2026-09-11 08:37:28 +02:00
CanbiZ (MickLesk) 73a8c55c9d passwordpusher: restore data before running migrations (#17141) 2026-09-11 07:43:04 +02:00
CanbiZ (MickLesk) de9b2f7ff3 paperclip: install the rust toolchain needed by the runner build (#17142) 2026-09-11 07:42:37 +02:00
CanbiZ (MickLesk) c001360b2d Rename lxc-delete.sh to guest-delete.sh (#17152) 2026-09-11 07:42:12 +02:00
CanbiZ (MickLesk) 785d33be40 core.func: fall back to a usable HOME when the shell has none (#17154) 2026-09-11 07:41:44 +02:00
CanbiZ (MickLesk) e253713148 homepage: run next directly instead of through pnpm (#17155) 2026-09-11 07:41:21 +02:00
CanbiZ (MickLesk) 7304dec635 update-apps: rewrite the retired Gitea base in every container before updating it (#17156) 2026-09-11 07:40:57 +02:00
CanbiZ (MickLesk) 28c18b735b issue template: add PVE release, execution context and phase; refresh distro list (#17160) 2026-09-11 07:40:36 +02:00
MickLesk 902b341327 Merge branch 'main' of https://github.com/community-scripts/ProxmoxVE into feat/guest-delete-vms 2026-09-10 10:39:42 +02:00
MickLesk cca5e8320a lxc-delete: also delete VMs, not just containers
One checklist now lists containers and VMs side by side, each tagged with its
type, with separate ALL CT / ALL VM entries. VMs stop via qm stop and are
removed with qm destroy --purge --destroy-unreferenced-disks.

Two fixes fall out of the rework: the destroy exit status is read from the
background job rather than from the spinner, so failures actually surface, and
a guest is only stopped once its deletion is confirmed.
2026-09-10 10:38:39 +02:00
CanbiZ (MickLesk) 810a6d2e82 vm: drop the discussions link from the summary (#17117) 2026-09-09 19:54:30 +02:00
MickLesk afff8c91cd Omada: resolve libssl1.1 from the Debian pools instead of a pinned URL
bullseye left security.debian.org when its LTS ended, so the hardcoded
libssl1.1_1.1.1w-0+deb11u8 filename now 404s. Scan the security, the
security-archive and the archive pools and take the newest build on offer
for the host architecture.

Closes #17104
2026-09-08 16:44:04 +02:00
CanbiZ (MickLesk) a3c029c341 Update Jellyfin FFmpeg dependency to version 8 (#17109) 2026-09-08 10:28:42 +02:00
CanbiZ (MickLesk) c039a297b3 flatnotes: follow upstream move to uv and Python 3.13 (#17090) 2026-09-07 16:37:07 +02:00
MickLesk b99dab130c node drift: label bump PRs so they reach the changelog 2026-09-07 14:25:44 +02:00
CanbiZ (MickLesk) 653341829f github: Open per-script Node bump PRs (#17065) 2026-09-07 12:53:38 +02:00
CanbiZ (MickLesk) 9e42f4b4a8 netboot-xyz: add Secure Boot and Legacy assets (#17066) 2026-09-07 12:52:48 +02:00
CanbiZ (MickLesk) dfb33d9559 heimdall: set up PHP 8.4 on update, keep only the database, run migrations (#17067) 2026-09-07 12:52:27 +02:00
CanbiZ (MickLesk) 7deac8444e reactive-resume: repair any wrong WorkingDirectory on update (#17068) 2026-09-07 12:52:04 +02:00
CanbiZ (MickLesk) f6185c0b1d mediamtx: keep mediamtx.yml across updates (#17069) 2026-09-07 12:51:42 +02:00
CanbiZ (MickLesk) 960e50f428 omnitools: allow remote action while npm ci (#17070) 2026-09-07 12:51:24 +02:00
CanbiZ (MickLesk) d4771cbf98 authentik: scope blueprints chown to avoid recursing into the mp0 bind mount (#17008) 2026-09-05 22:41:58 +02:00
CanbiZ (MickLesk) 535f2f2d2e iventoy: run iventoy.sh with bash instead of dash (#17034) 2026-09-05 22:41:32 +02:00
CanbiZ (MickLesk) 166c798e35 frigate: restart go2rtc.service before frigate starts (#17035) 2026-09-05 22:41:14 +02:00
CanbiZ (MickLesk) 89f179e05e snapotter: seed AI venv base packages on arm64, warn amd64 has no working CPU bundle (#16903) 2026-09-05 13:04:53 +10:00
CanbiZ (MickLesk) 9c750ffaf5 update-apps: follow renamed ct/ scripts instead of erroring out (#16991)
A container keeps the slug it was built with, so a renamed ct/ script leaves
the updater looking for a name that no longer exists.

Reported for pbs, renamed to proxmox-backup-server in 0e5f663df. The Alpine
merge on 2026-08-18 retired 29 more names the same way, so every container
installed from an alpine-* script before that date hits this too.

Candidates are only accepted when the target script really exists, so an
unknown slug still errors rather than running some other app's updater.

Fixes #16989
2026-09-05 13:04:27 +10:00
CanbiZ (MickLesk) d9c276c49c tolgee: bump required JDK from 21 to 25 (#17005) 2026-09-05 13:03:57 +10:00
CanbiZ (MickLesk) cfb0bfe4ac Refactor FileFlows: Stop Spinner before read -rp / Switch from "Node" to "Agent" (#17007)
* FileFlows Node: Stop Spinner before read -rp

* fileflows: update install path for Node->Agent rename, detect service unit dynamically

* fileflows: tolerate no pre-existing fileflows units when checking for the new Agent unit
2026-09-05 13:03:40 +10:00
CanbiZ (MickLesk) 1d1fd98d05 romm: write real version into backend/__version__.py placeholder (#17009) 2026-09-05 13:02:40 +10:00
CanbiZ (MickLesk) c272987bad Fix npm v12 allow-git/allow-remote restrictions across affected scripts (#17014)
* bentopdf: allow remote npm dependency for xlsx under npm v12

* librechat: allow remote npm dependency for xlsx under npm v12

* pangolin: allow remote npm dependencies for iron-remote-desktop packages under npm v12

* baserow: allow remote npm dependency for xlsx under npm v12

* cryptpad: allow git-based npm dependencies for drawio and json.sortify under npm v12
2026-09-04 17:52:31 +02:00
CanbiZ (MickLesk) 15b457b46d romm: allow git-based npm dependency for rom-patcher under npm v12 (#16990) 2026-09-03 16:04:50 +02:00
CanbiZ (MickLesk) d1855048f0 Pin Go to the version each project declares in go.mod (#16976) 2026-09-03 15:45:59 +02:00
CanbiZ (MickLesk) 68b5d96f64 Enhance backup process in teddycloud.sh (#16946) 2026-09-02 16:31:00 +02:00
CanbiZ (MickLesk) 65e5c87a33 Scripts: use shared core bootstrap for final 114 Script Batch (#16953)
Replaces the misc/build.func bootstrap with the two-root core loader.
No other change: the engine contract (var_*, update_script, start,
build_container, description) is identical on both engines.

versitygw.sh additionally gains a trailing newline; it lacked one.

With this batch every ct/ script is on the core engine.
2026-09-02 21:37:36 +10:00
CanbiZ (MickLesk) be84c3e1c1 Scripts: use shared core bootstrap for next 115 Script Batch (#16952)
Replaces the misc/build.func bootstrap with the two-root core loader.
No other change: the engine contract (var_*, update_script, start,
build_container, description) is identical on both engines.
2026-09-02 13:18:14 +02:00
CanbiZ (MickLesk) 277c782191 Scripts: use shared core bootstrap for next 115 Script Batch (#16951)
Replaces the misc/build.func bootstrap with the two-root core loader.
No other change: the engine contract (var_*, update_script, start,
build_container, description) is identical on both engines.
2026-09-02 21:14:48 +10:00
CanbiZ (MickLesk) f257cfdf89 Scripts: use shared core bootstrap for next 100 Script Batch (#16950) 2026-09-02 11:40:00 +02:00
CanbiZ (MickLesk) 1a06e9628c Move the next 25 scripts onto the core engine (#16934)
The 25 most-installed ct scripts still on misc/build.func, by install
count: homarr, influxdb, sonarr, radarr, networkoptimizer, authentik,
stirling-pdf, seerr, prowlarr, searxng, wordpress, zabbix, omada,
homeassistant, pegaprox, crafty-controller, iventoy, homelable,
flaresolverr, metube, netbird, casaos, obsidian-livesync, npmplus,
wazuh. ProxmoxVE goes from 115 migrated to 140.

Same three checks as #16749, since "migrate" has meant more than a line
swap before:

  - None of the 25 has an alpine-* variant, so there is no merge to do.
  - None references misc/ outside its bootstrap line.
  - Two functions exist only in misc/ (_gl_asset_urls,
    _send_abort_telemetry) and none of the 25 calls either.

So it is one line per script. Every head is byte-identical to the ones
migrated earlier, each diff is exactly 3+/1-, and all 25 parse.

Worth watching: scanopy is not in this set but sits at 32.9% success,
and casaos at 49.4% and networkoptimizer at 48.6% are in it. If those
two move, the engine is one changed variable among others.
2026-09-01 13:28:55 +02:00
CanbiZ (MickLesk) 97a36be502 jellyfin: verify repo suite via fallback chain and use ensure_dependencies for clearer apt failures (#16916) 2026-09-01 07:45:58 +02:00
MickLesk 75d33e16bd gh action: fix appid 2026-08-31 21:59:27 +02:00
MickLesk 535823a0fa Merge branch 'main' of https://github.com/community-scripts/ProxmoxVE 2026-08-31 21:58:11 +02:00
MickLesk 165c337c48 Use a distinct name for the PR app, which is not the header generator
vars.APP_ID named two different apps: 1065612 (community-scripts-pr-app)
here, 1108144 (app-header-generator) in ProxmoxVED. Folding both into
one GHAPP_HEADERS_ID would have pointed this repo at the wrong app, so
the PR app gets its own name.
2026-08-31 21:58:09 +02:00
CanbiZ (MickLesk) 3bb92c5a54 omv: migrate to new package repo host (packages.openmediavault.org is dead) (#16918) 2026-08-31 18:37:10 +02:00
CanbiZ (MickLesk) 6a5a714d18 openwebui: add UV_HTTP_TIMEOUT and retry loop to prevent uv install hangs (#16917) 2026-08-31 18:36:40 +02:00
CanbiZ (MickLesk) 8639310cfa Rename CI credentials to org-wide names, demote non-secrets to variables (#16919) 2026-08-31 18:35:56 +02:00
CanbiZ (MickLesk) 82dc3a6dec vaultwarden: relax cargo release profile via env vars to avoid build OOM (#16915) 2026-08-31 16:30:47 +02:00
CanbiZ (MickLesk) ea798df13a yuvomi/aurral: bump NODE_VERSION per upstream requirements (#16913) (#16914) 2026-08-31 16:30:11 +02:00
CanbiZ (MickLesk) d9eb574517 bambuddy: force asyncio loop, uvloop breaks camera proxy handlers (#16904) 2026-08-31 13:40:34 +02:00
CanbiZ (MickLesk) 82ee37f846 kima-hub/maintainerr/planka/spliit: bump NODE_VERSION (#16905) 2026-08-31 13:38:45 +02:00
CanbiZ (MickLesk) 6cae1ed744 bookorbit: raise service start timeout, migration can exceed systemd default (#16860) 2026-08-31 09:41:09 +02:00
CanbiZ (MickLesk) cecd3222fc filebrowser-quantum: strip removed disableIndexing key on update, restart service (#16892) 2026-08-31 09:40:58 +02:00
CanbiZ (MickLesk) b1edc2722d gatus: pin Go to gatus's go.mod version, modernize Alpine path to shared helpers (#16893) 2026-08-31 09:40:55 +02:00
CanbiZ (MickLesk) 6713f7e17f haos-vm: add optional x86-64-v2-AES CPU option, future HA numpy builds need it (#16868) 2026-08-31 08:52:51 +02:00
CanbiZ (MickLesk) dbb28d54e2 Include engine pull requests in the changelog (#16867) 2026-08-31 08:52:00 +02:00
CanbiZ (MickLesk) c45ce24995 immich: tolerate enable-maintenance-mode crash, same as disable-maintenance-mode (#16866) 2026-08-31 08:50:44 +02:00
CanbiZ (MickLesk) 5a71eb99f7 move the hardware-accelerated scripts onto new core (#16864) 2026-08-31 08:50:21 +02:00
CanbiZ (MickLesk) 97c00113be ntopng: use ntop.org's documented apt repo per Debian codename, not always apt-stable (#16862) 2026-08-31 08:49:57 +02:00
CanbiZ (MickLesk) fd13dff335 Refactor: OpenGist (#16861) 2026-08-31 08:49:37 +02:00
CanbiZ (MickLesk) 3921f056f4 node-red: remove --unsafe-perm flag (#16859) 2026-08-31 08:49:03 +02:00
CanbiZ (MickLesk) 35b378761c directus: add build-essential dependency (#16858) 2026-08-31 08:48:43 +02:00
CanbiZ (MickLesk) c152912552 general: remove gitea links overall (#16863)
* docker-vm, pve-privilege-converter: source from GitHub raw instead of gitea mirror

* docker-vm, pve-privilege-converter, vm-core.func: source from GitHub raw instead of gitea mirror
2026-08-30 12:52:43 +02:00
CanbiZ (MickLesk)andSam Heinz ceb783d62c github action: post the command that tests a ct/ or install/ change (#16833)
* Post the command that tests a ct/ or install/ change

Reviewing a script change meant working out the URL yourself, and the
obvious guess is wrong: curling the branch URL alone gives you the ct/
script from the PR and the install/ script from main, because each script
pins _CS_DEFAULT_URL to main and that pin is what fills
COMMUNITY_SCRIPTS_URL when it is unset. Frequently the install script is
the only thing that changed.

So the comment spells out both lines, per changed app.

Only for scripts already on the core bootstrap. The older one-liner
resolves everything from ProxmoxVE/main and ignores the variable, so a
command built for it would install main and look like it passed --  worse
than no comment. Those are named instead, with what to do about them.

pull_request_target for fork PRs, and nothing from the PR is checked out
or executed: the file list and the bootstrap line come from the API, and
a branch name that is not [A-Za-z0-9._/-]+ stops the run rather than
reaching a fenced code block.

* Update .github/workflows/pr-test-command.yml

Co-authored-by: Sam Heinz <sam@samheinz.com>

---------

Co-authored-by: Sam Heinz <sam@samheinz.com>
2026-08-29 23:38:09 +02:00
CanbiZ (MickLesk) a61c3882b5 homepage: set CI=true so pnpm can self-heal node_modules without a TTY (#16841) 2026-08-28 17:09:26 +02:00
CanbiZ (MickLesk) c1cff5ce2e Refactor: Calibre-Web database creation (#16842)
* calibre-web: point cps at explicit db path, src-layout package has no default anymore

* calibre-web: fix empty-library bootstrap, migrate pre-existing library on update
2026-08-29 00:59:06 +10:00
CanbiZ (MickLesk) 7b1c60f57a droppedneedle: launch via automatic_upgrade orchestrator, not raw target_main:app (#16834) 2026-08-28 14:32:00 +02:00
CanbiZ (MickLesk) 374230d387 calibre-web: point cps at explicit db path, src-layout package has no default anymore (#16832) 2026-08-28 21:11:22 +10:00
CanbiZ (MickLesk) e87cc87857 podman: pull portainer images before systemd unit start to avoid start timeout (#16831) 2026-08-28 21:10:20 +10:00
CanbiZ (MickLesk) 81ad04344d mastodon: read .ruby-version dynamically instead of hardcoding 4.0.5 (#16829) 2026-08-28 21:09:57 +10:00
CanbiZ (MickLesk) b194287cd5 gitea: make gitea own its home dir instead of toggling group perms (#16830) 2026-08-28 21:09:33 +10:00
CanbiZ (MickLesk) 4168f6c5d4 endurain: migrate legacy FRONTEND_DIR path on update (#16794) 2026-08-26 21:26:31 +02:00
CanbiZ (MickLesk) ab1869fbb0 tools.func: recognize bare XZ-compressed tarballs in fetch_and_deploy* (#16796) 2026-08-26 21:25:51 +02:00
CanbiZ (MickLesk) 416deb8fd0 tools.func: fix mongodb version comparison, guard apt purge against removing dependents (#16795) 2026-08-26 21:24:33 +02:00
CanbiZ (MickLesk) 87b9d51761 github: teach the PocketBase bot every field (#16781)
* Teach the PocketBase bot every field

The bot covered most of script_scripts but not categories, has_arm,
execute_in or app_vars, so those had to be edited by hand in the admin UI.

categories is a relation, so names are resolved against script_categories
and ids are accepted too - a copy out of the PocketBase UI works either way.
app_vars is a JSON column and rides the code-block 'set' path with its
content parsed rather than stored verbatim, so readers get an object.

cpu/ram/hdd/os/version live inside install_methods, and '/pocketbase immich
hdd=25' is how people ask for them. They now route to the default (non-Alpine)
method instead of being rejected as unknown fields, the reply names which
method was touched, and the value syncs into ct/<slug>.sh like the 'method'
path already does.

* Add screenshots and type to the bot

Two gaps were left. type is a relation to z_ref_script_types, so it needs the
same name-to-id resolution as categories - people write "ct", not a
fifteen-character id. Screenshots had no command at all.

The screenshot subcommand hands the URLs to the frontend's /api/screenshots
rather than fetching images inside a workflow. That endpoint already checks
the content type and size and attaches the file to PocketBase; doing it a
second time here would be a second set of bugs. It needs
SCREENSHOT_IMPORT_SECRET, and says so plainly when it is missing instead of
failing halfway.

slug stays deliberately out of reach. It is the URL, the JSON filename and the
ct/<slug>.sh path at once, so renaming it is a migration rather than an edit,
and the help text now says that instead of leaving people to wonder.
2026-08-26 13:18:14 +02:00
MickLesk 1f109e5714 gitea: fix ordering regression, chmod 750 before ln -s broke symlink creation 2026-08-25 16:04:44 +02:00
CanbiZ (MickLesk) 8854585a1a Migrate the (remaining) Top 25 scripts to the new core engine (#16749)
* Move the top 25 scripts onto the core engine

The engine work of the last few days reaches 30 of 561 ct scripts, about 5% of
ProxmoxVE traffic: retry on engine downloads, exit 227 instead of a misfiled
dpkg error, the umask fix that stops a hardened host producing containers apt
cannot resolve in, the TMPDIR guard, the toolchain restore. All of it has been
sitting where almost nobody runs it.

All eighteen at once rather than in waves. A slow rollout does not exercise the
paths only some scripts take, and broad exposure is what surfaces bugs -- a
deliberate call about release risk.

Checked before touching anything, because "migrate" meant far more than a line
swap last time:

  - None of the eighteen has an alpine-* variant, so there is no merge to do.
  - No script references misc/ outside its bootstrap line.
  - Of the 61 functions that exist only in misc/, none is called by any of them.

So it is one line per script, and every head is now byte-identical to the ones
migrated earlier. With these, ProxmoxVE goes from 30 scripts on the core engine
to 48 -- and from roughly 5% of traffic to the majority, since these are the
ones people actually install.

Two to watch: immich sits at 44.7% success and vaultwarden at 42.1% before
this. If their numbers move, the engine is one of two changed variables rather
than the only one.

* Move update-apps onto the core engine

Entry 11 of the list and the only one that is not a ct script, so it was left
out of the previous commit. It is a host tool: it never used build.func at all,
it sources misc/core.func and misc/api.func directly.

The swap is therefore two lines rather than one, and worth checking rather than
assuming. It uses exactly five engine functions -- header_info,
init_tool_telemetry, msg_info, msg_ok, msg_error -- all present in the core, and
both files load standalone, which they had not had to do before: everywhere else
they arrive through build.func.

That completes the list. All 25 now run on the core engine.

Fixing this one matters beyond the migration: update-apps is what drives
unattended updates across every container on a host, and it is the path where
PHS_SILENT was being ignored (#16593). It now gets the engine that honours it.
2026-08-25 11:04:15 +02:00
CanbiZ (MickLesk) 4c6ccdde35 fireshare: source fireshare.env during update instead of hardcoding defaults (#16706) 2026-08-24 14:06:30 +02:00
CanbiZ (MickLesk) a876ad22bb netbox: serve on plain HTTP too, port 80 forced HTTPS redirect broke reverse proxies (#16707)
* netbox: serve on plain HTTP too, port 80 forced HTTPS redirect broke reverse proxies

* Update netbox-install.sh for Apache configuration

Modify Apache configuration to serve NetBox on port 80.
2026-08-24 13:51:03 +02:00
CanbiZ (MickLesk) 3c56af9f33 fileflows: update download URL, old /downloads/zip endpoint returns 404 (#16708) 2026-08-24 13:45:56 +02:00
CanbiZ (MickLesk) d1dd9e18e4 post-pve/pbs-install: fix component_exists_in_sources matching substrings of hyphenated tokens (#16709)
* post-pve-install: fix component_exists_in_sources matching substrings of hyphenated tokens

* post-pbs-install: fix component_exists_in_sources matching substrings of hyphenated tokens
2026-08-24 13:45:15 +02:00
CanbiZ (MickLesk) 566c203a34 Gitea: fix git-over-SSH auth, group-writable home dir tripped sshd StrictModes (#16710)
* gitea: fix git-over-SSH auth, group-writable home dir tripped sshd StrictModes

* Update gitea-install.sh
2026-08-24 13:40:43 +02:00
CanbiZ (MickLesk) 065f34aefe build.func: allow default.vars to raise var_cpu/var_ram/var_disk above app baseline (#16704) 2026-08-24 07:44:47 +02:00
CanbiZ (MickLesk)andTobias a35a75eadb Set default ProxmoxVE raw URL in PVE-UPS & fix var_cpu sorting (#16689)
* Set default ProxmoxVE raw URL in UPS script

Define `_CS_DEFAULT_URL` at the top of `ct/pve-ups.sh` and remove the outdated bootstrap comments, aligning the script with the newer URL-default pattern used for script sourcing.

* Branch var_cpu by OS where the two variants actually differ

The merged scripts branch var_ram, var_disk and var_version on var_os but
left var_cpu above the branch, so both variants inherited the Debian value.
On Vaultwarden that meant an Alpine container was told it wanted four cores
for an update that runs apk and restarts a service.

Only seven scripts are affected. Comparing each merged script against the
alpine-* script it replaced, 22 of the 29 already had the same CPU count on
both sides, so moving the line there would be churn with no behaviour change.
These seven did not:

  docker, forgejo, ironclaw, syncthing, transmission, zigbee2mqtt   2 -> 1
  vaultwarden                                                       4 -> 1

The Alpine values are the ones those scripts carried before the merge, read
back out of the deleted alpine-* files rather than picked. The Debian arm
keeps what it has now.

Needs the matching core change: until build.func derives var_os inside a
container, an update never reaches the Alpine arm at all.

* fix: source url

* Update script to source build functions from URLs

---------

Co-authored-by: Tobias <96661824+CrazyWolf13@users.noreply.github.com>
2026-08-23 03:21:42 +02:00
CanbiZ (MickLesk) d59a673211 docuseal: use DocuSeal's patched PDFium build to fix service start (#16673)
DocuSeal switched to its own PDFium fork (upstream commit "adjust pdfium",
2026-08-15) and now attaches functions that only exist in that build, e.g.
FPDFPage_GetAnnotCountRaw from the added fpdf_annots_raw.h. The generic
bblanchon/pdfium-binaries library the script installed does not export them,
so lib/pdfium.rb raises FFI::NotFoundError while Rails eager-loads and both
docuseal.service and docuseal-sidekiq.service fail to start:

  Unable to load application: FFI::NotFoundError: Function
  'FPDFPage_GetAnnotCountRaw' not found in [libpdfium.so]

Install the library from docusealco/pdfium-binaries instead, matching the
upstream Dockerfile. It is only published as a musl build (DocuSeal's image is
Alpine based), so the musl runtime is installed and its library directory is
added to the loader search path - the shared object needs "libc.so" (musl) at
dlopen time. Verified on glibc: the library loads, resolves the raw annotation
functions and renders pages correctly.

The update path now refreshes PDFium too, so existing containers are repaired
by running "update" even when DocuSeal itself is already up to date.
2026-08-22 06:30:08 +02:00
CanbiZ (MickLesk) 288a40e96f immichframe: strip invalid UUID placeholders from default Settings.yml (#16660) 2026-08-21 10:37:12 +02:00
CanbiZ (MickLesk) 9d8b78daca openziti-controller: redirect stdin from /dev/null to skip postinst's interactive bootstrap prompt (#16650) 2026-08-21 08:08:33 +02:00
CanbiZ (MickLesk) 3b3a5e7d29 bookorbit: bump default RAM to prevent tsc OOM segfault during nest build (#16649) 2026-08-21 08:05:08 +02:00
CanbiZ (MickLesk) d2fe695c49 immich: split jpegli into its own build step, resolve library revisions dynamically (#16656) 2026-08-21 07:55:32 +02:00
CanbiZ (MickLesk) a4542eacb3 tdarr: make unzip non-interactive to prevent hang on repeat/automated updates (#16648) 2026-08-21 07:24:22 +02:00