Compare commits

...

134 Commits

Author SHA1 Message Date
Tobias
08ca5b1c84 Remove outdated comment from caddy.sh 2026-10-11 16:13:43 +02:00
MickLesk
48843e0d5f Caddy: install the .deb from GitHub instead of the Cloudsmith repo
Cloudsmith answered 402 Payment Required for two days once Caddy's
bandwidth quota ran out, and upstream expects it to happen again
(caddyserver/dist#142). Each GitHub release carries the identical
package (same SHA256), so Debian installs it from there now. The update
drops the Cloudsmith source, seeds ~/.caddy from the installed package
so nothing is reinstalled, and keeps a customised Caddyfile.
2026-10-11 15:57:19 +02:00
community-scripts-pr-app[bot]
fb82f7084a Update CHANGELOG.md (#17861)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 13:44:32 +00:00
CanbiZ (MickLesk)
7198d218be Let var_* answer the optional add-on prompts (#17858)
Thirty-six yes/no prompts for optional components in 26 install
scripts could only be answered at the terminal, so an unattended
install stopped at the first one. Each now takes var_<app>_<option>
first and still asks when it is unset. The four conditions that only
matched a single y now take yes as well, since that is what the website
sends.
2026-10-11 15:44:05 +02:00
community-scripts-pr-app[bot]
afdd1560ae Update CHANGELOG.md (#17860)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 13:37:59 +00:00
CanbiZ (MickLesk)
560bd81537 Confirm third-party installers through confirm_external_installer (#17857)
The thirteen install scripts and two update paths that run an external
installer each carried the same warning and y/N read. The core helper
does the same and also takes var_external_installer, so unattended
installs can answer it. Needs community-scripts/core
feat/confirm-external-installer merged first.
2026-10-11 15:37:33 +02:00
community-scripts-pr-app[bot]
33f516930b Update CHANGELOG.md (#17859)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 13:07:05 +00:00
community-scripts-pr-app[bot]
bbcea041e7 Update CHANGELOG.md (#17856)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 12:20:11 +00:00
push-app-to-main[bot]
386bb80e1e Add cinephage (ct) (#17852)
Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
2026-10-11 14:19:42 +02:00
community-scripts-pr-app[bot]
61336cd55e Update CHANGELOG.md (#17855)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 12:18:10 +00:00
CanbiZ (MickLesk)
6b8698fe87 hermesagent: match the relaunched root gateway regardless of interpreter (#17847)
* hermesagent: match the relaunched root gateway regardless of interpreter

Upstream now starts the gateway through its bundled python via runpy, so
the venv-path pattern from #17126 matched nothing and the root gateway
survived; its writes then raced chown -R and aborted the update.

* Clean up comments in hermesagent.sh

Removed comments regarding hermes update and matching patterns.
2026-10-11 14:17:43 +02:00
community-scripts-pr-app[bot]
548e855118 Update CHANGELOG.md (#17853)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 12:03:34 +00:00
CanbiZ (MickLesk)
de19f51761 Radicale: install the bcrypt and argon2 extras (#17813)
* Radicale: install the bcrypt and argon2 extras

The update replaces pyproject.toml and the venv, so a bcrypt or argon2
module added by hand was gone afterwards and Radicale refused to start
with htpasswd_encryption = bcrypt, argon2 or autodetect. The service now
runs uv with --extra bcrypt --extra argon2, which upstream already
defines. The update patches existing units and restarts the service.

* Radicale: enable the extras only once the code defines them

argon2 is an extra since v3.5.4 and uv refuses unknown extras, so patching
before the release update broke older installs. Patch after it instead,
and only when pyproject.toml defines the extra.
2026-10-11 14:03:06 +02:00
community-scripts-pr-app[bot]
ad700e9691 Update CHANGELOG.md (#17851)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 11:24:54 +00:00
CanbiZ (MickLesk)
91bc5b3835 docker: take the lxcfs toggle, TCP socket and Compose choice from app variables (#17850)
* docker: take the lxcfs toggle, TCP socket and Compose choice from app variables

var_docker_lxcfs is exported for the core helper; var_docker_tcp_socket
(no/local/all) and var_docker_compose replace the prompts when set, so
the website generator can offer them. Alpine wrote daemon.json through
silent(), which captured the output and left the file empty.

* docker: use var_docker_socket, the name the catalog record already carries
2026-10-11 13:24:31 +02:00
community-scripts-pr-app[bot]
701268bff4 Update CHANGELOG.md (#17849)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 08:28:49 +00:00
community-scripts-pr-app[bot]
c1c7437ddc Update CHANGELOG.md (#17848)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 07:16:36 +00:00
community-scripts-pr-app[bot]
9c11f496c7 Update CHANGELOG.md (#17846)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 07:12:28 +00:00
community-scripts-pr-app[bot]
46196d179e Update CHANGELOG.md (#17844)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 06:50:36 +00:00
petermnt
3035f9216e fix(zigbee2mqtt): preserve backup stream and prevent filename collisions (#17751)
* fix(zigbee2mqtt): preserve backup tar stream in quiet mode

* fix(zigbee2mqtt): avoid backup collisions on repeated updates
2026-10-11 08:50:08 +02:00
community-scripts-pr-app[bot]
c80a171b36 Update CHANGELOG.md (#17840)
Some checks failed
Create Changelog Pull Request / update-changelog-pull-request (push) Has been cancelled
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 00:05:37 +00:00
community-scripts-pr-app[bot]
699228f646 Archive old changelog entries (#17839)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 00:05:12 +00:00
community-scripts-pr-app[bot]
31597fa698 Update CHANGELOG.md (#17838)
Some checks failed
Create Changelog Pull Request / update-changelog-pull-request (push) Has been cancelled
Set state to is_deleted in pocketbase / delete-pocketbase-entry (push) Has been cancelled
Sync ct/install to Incus / dispatch (push) Has been cancelled
Update script timestamp on .sh changes / update-script-timestamp (push) Has been cancelled
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-10 20:49:42 +00:00
push-app-to-main[bot]
0a8c97c765 Add weblate (ct) (#17837)
Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
2026-10-10 22:49:16 +02:00
community-scripts-pr-app[bot]
1bcd22137e Update CHANGELOG.md (#17834)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-10 14:30:13 +00:00
Johann Grobe
1bc4191951 update endurain repo from codeberg to gh (#17831)
* fix: endurain repo

* fix: endurain release check
2026-10-10 16:29:43 +02:00
community-scripts-pr-app[bot]
d1bad678e9 Update CHANGELOG.md (#17832)
Some checks failed
Create Changelog Pull Request / update-changelog-pull-request (push) Has been cancelled
Set state to is_deleted in pocketbase / delete-pocketbase-entry (push) Has been cancelled
Sync ct/install to Incus / dispatch (push) Has been cancelled
Update script timestamp on .sh changes / update-script-timestamp (push) Has been cancelled
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-10 10:28:07 +00:00
Clayton Faria
2d12d0e0b1 Immich: download countryInfo.txt into the geodata directory on update (#17823) 2026-10-10 12:27:40 +02:00
community-scripts-pr-app[bot]
cd06638952 Update CHANGELOG.md (#17829)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-10 07:11:43 +00:00
community-scripts-pr-app[bot]
65ee461b14 Update CHANGELOG.md (#17828)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-10 07:11:20 +00:00
push-app-to-main[bot]
9fdbb10a45 Add certmate (ct) (#17803)
Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
2026-10-10 09:11:09 +02:00
push-app-to-main[bot]
e274342a54 Add anythingllm (ct) (#17802)
Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
2026-10-10 09:10:51 +02:00
community-scripts-pr-app[bot]
05fd051fb6 Update CHANGELOG.md (#17826)
Some checks failed
Create Changelog Pull Request / update-changelog-pull-request (push) Has been cancelled
Set state to is_deleted in pocketbase / delete-pocketbase-entry (push) Has been cancelled
Sync ct/install to Incus / dispatch (push) Has been cancelled
Update script timestamp on .sh changes / update-script-timestamp (push) Has been cancelled
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-10 05:22:40 +00:00
Austin
c5c107c374 paperclip: honor custom PAPERCLIP_HOME on update (#17825)
The update path chowned a hardcoded /opt/paperclip-data and always moved
root-run services to a dedicated user. Installs that keep their data
elsewhere (for example an NFS bind mount reachable only by root) failed
with "chown: cannot access '/opt/paperclip-data'" after the rebuild, and a
non-root user could not have reached that data anyway.

Read PAPERCLIP_HOME from the install's .env. Keep the service as root when
it points somewhere other than /opt/paperclip-data, and only chown
/opt/paperclip-data when it is the configured data dir and exists.

Co-authored-by: root <root@paperclip.pilz.dev>
Co-authored-by: Claude <noreply@anthropic.com>
2026-10-10 07:22:13 +02:00
community-scripts-pr-app[bot]
8e11d877b9 Update CHANGELOG.md (#17818)
Some checks failed
Create Changelog Pull Request / update-changelog-pull-request (push) Has been cancelled
Set state to is_deleted in pocketbase / delete-pocketbase-entry (push) Has been cancelled
Sync ct/install to Incus / dispatch (push) Has been cancelled
Update script timestamp on .sh changes / update-script-timestamp (push) Has been cancelled
Stale PR Management / stale-prs (push) Has been cancelled
Lock closed issues / lock (push) Has been cancelled
Create Daily Release / create-daily-release (push) Has been cancelled
Delete merged branches / delete-merged-branches (push) Has been cancelled
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-09 19:27:09 +00:00
community-scripts-pr-app[bot]
623a7a1cf2 Update CHANGELOG.md (#17817)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-09 19:24:33 +00:00
CanbiZ (MickLesk)
969cc5e9b8 FileBrowser Quantum: migrate the config and database to v2 (#17815)
v2.0.0 reads the config strictly and stops at the v1 keys the addon
wrote (server.port, conditionals, indexingIntervalMinutes). It also only
imports the old BoltDB when server.database.migrateFrom names it and no
database.db is left in the working directory. The update now rewrites
the config, renames the database and points migrateFrom at it, keeping
a copy of the v1 config. New installs write the v2 layout.
2026-10-09 21:24:00 +02:00
community-scripts-pr-app[bot]
14cd4cb667 Update CHANGELOG.md (#17814)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-09 18:44:20 +00:00
Sim Kai Long
63cf41174f OpenCloud: allow OpenCloud to embed Collabora on 26.04.4 (#17810)
Collabora 26.04.4 ignores frame-ancestors set in content_security_policy,
so the editor iframe is blocked. Use net.frame_ancestors (as
opencloud-compose does) on install, and add it on update when missing.
2026-10-09 20:43:49 +02:00
community-scripts-pr-app[bot]
daa4daa927 Update CHANGELOG.md (#17807)
Some checks failed
Create Changelog Pull Request / update-changelog-pull-request (push) Has been cancelled
Set state to is_deleted in pocketbase / delete-pocketbase-entry (push) Has been cancelled
Sync ct/install to Incus / dispatch (push) Has been cancelled
Update script timestamp on .sh changes / update-script-timestamp (push) Has been cancelled
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-09 10:08:36 +00:00
CanbiZ (MickLesk)
227526cf55 Immich: survive an interrupted update and a failing ML build (#17798)
* Immich: survive an interrupted update and a failing ML build

An update cancelled midway leaves /opt/immich/app empty, and the next run
died at once on cd /opt/immich/app/bin to enable maintenance mode (#17796).
Maintenance mode is now only toggled when immich-admin exists.

uv sync fetching the ml-models git dependency failed with "Could not resolve
host" behind DNS filters such as AdGuard while DNS itself worked (#17797);
running uv one download at a time got through. Retries now do that.

If machine learning still cannot be built, the update no longer stops with
maintenance mode on and every service down: it finishes, starts the web
service, puts the previous version back into ~/.immich so the next update
retries, and exits with an error. Updates are also announced as taking
5-15 minutes, since the first report came from cancelling one that looked
stuck.

* Immich: point immich-ml at the moved ml_start.sh and clear failed units

The update moves ml_start.sh into app/machine-learning, but only rewrote
immich-web's ExecStart, so older containers kept starting ML from
/opt/immich/ml_start.sh and failed with 203/EXEC. Rewrite immich-ml the same
way. A crash loop before the update can also leave both units rate-limited,
which makes the final restart fail; reset them first.
2026-10-09 12:08:08 +02:00
community-scripts-pr-app[bot]
d271571ff7 Update CHANGELOG.md (#17806)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-09 06:32:19 +00:00
push-app-to-main[bot]
7100f6521c FoldingAtHome (#17799)
* Add foldingathome (ct)

* Clean up comments in foldingathome.sh

Removed comments about Git tags and installation process.

* Clean up comments in foldingathome-install.sh

Removed outdated comments regarding package installation and configuration.

---------

Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
Co-authored-by: CanbiZ (MickLesk) <47820557+MickLesk@users.noreply.github.com>
2026-10-09 08:31:48 +02:00
community-scripts-pr-app[bot]
387b8bf542 Update CHANGELOG.md (#17805)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-09 06:30:17 +00:00
push-app-to-main[bot]
a56510bf57 LocalAI (#17801)
* Add localai (ct)

* Refactor localai.sh to clean up comments and exports

Removed comments regarding ARM64 support and clarified install script export variables.

* Refactor variable assignments and clean up comments

Rearranged variable assignments and removed comments about SQLite and PostgreSQL.

---------

Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
Co-authored-by: CanbiZ (MickLesk) <47820557+MickLesk@users.noreply.github.com>
2026-10-09 08:29:50 +02:00
community-scripts-pr-app[bot]
05bc39e623 Update CHANGELOG.md (#17804)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-09 06:27:55 +00:00
push-app-to-main[bot]
6db1ebe154 Tvheadend (#17800)
* Add tvheadend (ct)

* Update Tvheadend installation messages in script

---------

Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
Co-authored-by: CanbiZ (MickLesk) <47820557+MickLesk@users.noreply.github.com>
2026-10-09 08:27:27 +02:00
community-scripts-pr-app[bot]
f5afa5d4ed Update CHANGELOG.md (#17795)
Some checks failed
Create Changelog Pull Request / update-changelog-pull-request (push) Has been cancelled
Set state to is_deleted in pocketbase / delete-pocketbase-entry (push) Has been cancelled
Sync ct/install to Incus / dispatch (push) Has been cancelled
Update script timestamp on .sh changes / update-script-timestamp (push) Has been cancelled
Stale PR Management / stale-prs (push) Has been cancelled
Lock closed issues / lock (push) Has been cancelled
Create Daily Release / create-daily-release (push) Has been cancelled
Delete merged branches / delete-merged-branches (push) Has been cancelled
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-08 13:13:45 +00:00
CanbiZ (MickLesk)
bb1ec9e608 Homarr: replace the musl better-sqlite3 that v2.3.0 ships for Debian (#17789)
The build-debian tarballs of v2.3.0 carry the Alpine build of
better_sqlite3.node, so the DB migration dies with ERR_DLOPEN_FAILED on
libc.musl and Homarr no longer starts after an update (#17783,
homarr-labs/homarr#7097). When the bundled module is musl, swap in
better-sqlite3's own glibc prebuild for the running Node ABI. The update runs
the check outside the release check, so containers already on 2.3.0 are
repaired too; it does nothing once upstream ships a correct tarball.
2026-10-08 15:13:16 +02:00
community-scripts-pr-app[bot]
8befe84437 Update CHANGELOG.md (#17794)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-08 13:10:54 +00:00
CanbiZ (MickLesk)
c4879a1b72 CLIProxyAPI: keep plugins and data across updates (#17790)
The clean install wiped /opt/cliproxyapi including plugins/ and data/, so
every update removed installed plugins and their data (#17750).
2026-10-08 15:10:28 +02:00
CanbiZ (MickLesk)
bc29d4bb21 Kima-Hub: install the Python services into a uv venv (#17791)
pip3 installed into the system Python with PIP_BREAK_SYSTEM_PACKAGES and
stopped once a dependency wanted a newer idna than Debian's python3-idna,
which pip cannot uninstall (no RECORD file) (#17784). The analyzers now run
from /opt/kima-hub/venv on a uv-managed Python 3.13.
2026-10-08 15:10:05 +02:00
CanbiZ (MickLesk)
b087c0bbc3 Refactor: OPNsense VM (#17785) 2026-10-08 15:09:45 +02:00
CanbiZ (MickLesk)
2f8e318528 Refactor: Nextcloud VM (Turnkey) (#17787)
Updated authorship and improved script structure. Adjusted default settings and enhanced user prompts for creating a Nextcloud VM.
2026-10-08 15:09:33 +02:00
community-scripts-pr-app[bot]
d1c0bc50cd Update CHANGELOG.md (#17793)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-08 13:07:04 +00:00
CanbiZ (MickLesk)
f09085f553 Refactor: OpenWrt VM (#17774)
* Refactor: OpenWrt VM

* Refactor comments in openwrt-vm.sh

Removed redundant author line and cleaned up comments.
2026-10-08 15:06:00 +02:00
community-scripts-pr-app[bot]
632bfa43dc Update CHANGELOG.md (#17792)
Some checks failed
Create Changelog Pull Request / update-changelog-pull-request (push) Has been cancelled
Set state to is_deleted in pocketbase / delete-pocketbase-entry (push) Has been cancelled
Sync ct/install to Incus / dispatch (push) Has been cancelled
Update script timestamp on .sh changes / update-script-timestamp (push) Has been cancelled
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-08 13:05:23 +00:00
community-scripts-pr-app[bot]
3d7c129646 Update CHANGELOG.md (#17786)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-08 11:49:57 +00:00
push-app-to-main[bot]
6be105b961 Unifi-OS-Server VM (#17752)
* Add unifi-os-server-vm (vm)

* Refactor UniFi OS Server VM setup script

Updated the script to set default OS and version, improved error handling, and modified the first-boot installer process.

---------

Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
Co-authored-by: CanbiZ (MickLesk) <47820557+MickLesk@users.noreply.github.com>
2026-10-08 13:49:27 +02:00
community-scripts-pr-app[bot]
de430e8131 Update CHANGELOG.md (#17781)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-08 09:50:22 +00:00
CanbiZ (MickLesk)
0de4640699 Refactor: Ubuntu VM (#17776)
* Refactor: Ubuntu VM

Updated licensing information and improved error handling. Refactored OS selection logic and cloud-init prompts.

* Update license URL in ubuntu-vm.sh
2026-10-08 11:49:54 +02:00
community-scripts-pr-app[bot]
ba752598eb Update CHANGELOG.md (#17780)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-08 09:47:35 +00:00
CanbiZ (MickLesk)
84d2c964e6 Immich: Pin to 3.3.0 / Update ML Python to 3.13 (#17770)
* Immich: pin v3.3.0 again

Reapplies #17759, reverted in #17767 because machine learning broke on 3.3.0; the fixes follow.

* Immich: run machine learning on Python 3.13

3.3.0 requires Python >=3.12 for machine learning and upstream builds both its CPU and OpenVINO images on 3.13. The CPU path still pinned 3.11, so uv sync failed on every update and install (#17762).

* Immich: stop when uv sync keeps failing

After three failed attempts the loop still reported the machine-learning step as done, so an update ended in "Updated successfully" with no usable venv and immich-ml failing on start. Exit with an error instead.

* Immich: only mention the HEIC patch when it applies

On 3.3.0 the sharp call it rewrites is gone, so every run printed "pattern not found, skipped" into the spinner line and then "Patched". Check for the pattern first and stay silent otherwise.

* BookOrbit: retry the client build when the bundler crashes

Since rolldown 1.2.8, vite build dies at random with SIGSEGV or SIGBUS
(rolldown#10860, closed upstream), which stopped the 3.3.0 update with exit
139 (#17753). Retry the client build up to three times before giving up.
2026-10-08 11:47:06 +02:00
community-scripts-pr-app[bot]
6ffb433d5d Update CHANGELOG.md (#17779)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-08 09:25:42 +00:00
push-app-to-main[bot]
a2474baaf1 Add zimaos-vm (vm) (#17778)
Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
2026-10-08 11:25:15 +02:00
community-scripts-pr-app[bot]
005cdcdb2b Update CHANGELOG.md (#17777)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-08 09:13:30 +00:00
community-scripts-pr-app[bot]
8876248b54 Update CHANGELOG.md (#17775)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-08 08:38:16 +00:00
community-scripts-pr-app[bot]
7d2c2205b2 Update CHANGELOG.md (#17773)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-08 08:16:28 +00:00
community-scripts-pr-app[bot]
ab3f133d06 Update CHANGELOG.md (#17772)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-08 08:00:34 +00:00
community-scripts-pr-app[bot]
f9148e4fbc Update CHANGELOG.md (#17771)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-08 07:52:31 +00:00
community-scripts-pr-app[bot]
386a148e84 Update CHANGELOG.md (#17769)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-08 07:23:01 +00:00
community-scripts-pr-app[bot]
2c0a19263a Update CHANGELOG.md (#17768)
Some checks failed
Create Changelog Pull Request / update-changelog-pull-request (push) Has been cancelled
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-08 04:13:24 +00:00
CanbiZ (MickLesk)
2a38085984 Revert "Immich: Pin to v3.3.0 (#17759)" (#17767)
This reverts commit a5431e295b.
2026-10-08 06:13:00 +02:00
community-scripts-pr-app[bot]
5e8e2ef477 Update CHANGELOG.md (#17761)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-07 21:03:08 +00:00
Chris
a5431e295b Immich: Pin to v3.3.0 (#17759)
* Immich: Pin version to 3.3.0

- New features
- Bugfixes

* Enable new Machine Learning models by default
2026-10-07 23:02:37 +02:00
community-scripts-pr-app[bot]
7ddb0c68de Update CHANGELOG.md (#17756)
Some checks failed
Create Changelog Pull Request / update-changelog-pull-request (push) Has been cancelled
Set state to is_deleted in pocketbase / delete-pocketbase-entry (push) Has been cancelled
Sync ct/install to Incus / dispatch (push) Has been cancelled
Update script timestamp on .sh changes / update-script-timestamp (push) Has been cancelled
Stale PR Management / stale-prs (push) Has been cancelled
Lock closed issues / lock (push) Has been cancelled
Create Daily Release / create-daily-release (push) Has been cancelled
Delete merged branches / delete-merged-branches (push) Has been cancelled
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-07 19:40:30 +00:00
CanbiZ (MickLesk)
096f0ba2db AudioMuse-AI: replace the venv on update without asking (#17738)
uv venv on an existing .venv asks before replacing it and refuses outright
without a terminal, so updates through update-apps.sh failed and left the
services stopped (#17734). --clear replaces it the way the interactive prompt
did.
2026-10-07 21:40:00 +02:00
community-scripts-pr-app[bot]
b24d1e2631 Update CHANGELOG.md (#17755)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-07 19:39:27 +00:00
CanbiZ (MickLesk)
46c0210af7 Pangolin: Unpin Release, stable enough, Bump to latest (#17740)
* Pangolin: Unpin Release, stable enough, Bump to latest

* Remove default PANGOLIN_VERSION in install script
2026-10-07 21:39:05 +02:00
CanbiZ (MickLesk)
5af976eb97 Refactor: Archlinux-VM (#17741)
* Refactor archlinux-vm.sh and update defaults

Refactor Arch Linux VM script to improve structure and update default settings.

* Update Arch Linux VM script to use dynamic ISO path
2026-10-07 21:38:56 +02:00
community-scripts-pr-app[bot]
19a400c04b Update CHANGELOG.md (#17754)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-07 19:36:54 +00:00
CanbiZ (MickLesk)
712656a330 Refactor: MikroTik RouterOS (#17748)
* Refactor: MikroTik RouterOS

* Update COMMUNITY_SCRIPTS_URL to ProxmoxVE repository
2026-10-07 21:36:18 +02:00
MickLesk
3b768aaeb9 minor qf: update ISO handling in TrueNAS and Umbrel OS VM scripts 2026-10-07 16:00:36 +02:00
community-scripts-pr-app[bot]
008e2d90be Update CHANGELOG.md (#17749)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-07 13:23:39 +00:00
push-app-to-main[bot]
fa8b74a00b Add fedora-vm (vm) (#17747)
Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
2026-10-07 15:23:06 +02:00
community-scripts-pr-app[bot]
1dfe79f968 Update CHANGELOG.md (#17745)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-07 13:04:43 +00:00
community-scripts-pr-app[bot]
111a281b3e Update CHANGELOG.md (#17743)
Some checks failed
Create Changelog Pull Request / update-changelog-pull-request (push) Has been cancelled
Set state to is_deleted in pocketbase / delete-pocketbase-entry (push) Has been cancelled
Sync ct/install to Incus / dispatch (push) Has been cancelled
Update script timestamp on .sh changes / update-script-timestamp (push) Has been cancelled
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-07 12:06:30 +00:00
samvandenbossche
b755ec70d5 paperclip: run service as a dedicated non-root user (#17707)
Claude Code refuses --dangerously-skip-permissions as root, which blocked
Paperclip onboarding. Run onboarding and the systemd service as a
non-root user (var_paperclip_user, default paperclip) with an optional
var_paperclip_pass (account locked if unset). Existing installs are
migrated on update.

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-07 14:06:14 +02:00
community-scripts-pr-app[bot]
beff70719f Update CHANGELOG.md (#17742)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-07 12:06:00 +00:00
Sim Kai Long
cec9f13da1 OpenCloud: bump to v8.1.0, rebuild search index on upgrade (#17710)
v8 changes the search index format; existing files are not found by
search until the index is rebuilt. When updating from 7.x or older, run
the reindex as a transient systemd unit (the CLI cancels the rebuild if
interrupted), wait for it, and report the outcome.
2026-10-07 14:05:30 +02:00
community-scripts-pr-app[bot]
ea59019670 Update CHANGELOG.md (#17739)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-07 06:32:46 +00:00
CerberusStyle
13bfd8aa15 Thingsboard: update Java version from 17 to 25 (#17733)
* Update Java version from 17 to 25 in install script

* Set JAVA_VERSION before checking for gh release

---------

Co-authored-by: CanbiZ (MickLesk) <47820557+MickLesk@users.noreply.github.com>
2026-10-07 08:32:22 +02:00
community-scripts-pr-app[bot]
175bbe9da7 Update CHANGELOG.md (#17737)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-07 05:38:39 +00:00
community-scripts-pr-app[bot]
48706f41d5 Update CHANGELOG.md (#17730)
Some checks failed
Create Changelog Pull Request / update-changelog-pull-request (push) Has been cancelled
Set state to is_deleted in pocketbase / delete-pocketbase-entry (push) Has been cancelled
Sync ct/install to Incus / dispatch (push) Has been cancelled
Update script timestamp on .sh changes / update-script-timestamp (push) Has been cancelled
Stale PR Management / stale-prs (push) Has been cancelled
Lock closed issues / lock (push) Has been cancelled
Create Daily Release / create-daily-release (push) Has been cancelled
Delete merged branches / delete-merged-branches (push) Has been cancelled
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 15:39:40 +00:00
community-scripts-pr-app[bot]
017691457a Update CHANGELOG.md (#17729)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 14:29:29 +00:00
community-scripts-pr-app[bot]
17f5ac84e5 Update CHANGELOG.md (#17728)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 14:27:31 +00:00
community-scripts-pr-app[bot]
0b0ad2e9bd Update CHANGELOG.md (#17727)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 14:27:19 +00:00
community-scripts-pr-app[bot]
78a4d809c7 Update CHANGELOG.md (#17726)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 14:26:51 +00:00
CanbiZ (MickLesk)
36078aa896 Webtrees: stop serving data/ and the source folders directly (#17724)
Caddy served all of /opt/webtrees through file_server, so media under
data/media could be fetched by URL without passing webtrees' privacy rules.
webtrees only protects data/ with an .htaccess, which Caddy ignores. Deny the
folders webtrees' own nginx guide keeps private, plus dotfiles.

update_script adds the rule to existing Caddyfiles on every update, not only
when a new release is out, and keeps the old file if the result fails
caddy validate.
2026-10-06 16:26:21 +02:00
community-scripts-pr-app[bot]
69bbf389f3 Update CHANGELOG.md (#17725)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 14:23:09 +00:00
community-scripts-pr-app[bot]
1da0c463ca Update CHANGELOG.md (#17723)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 13:54:15 +00:00
community-scripts-pr-app[bot]
745f88d484 Update CHANGELOG.md (#17722)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 13:53:39 +00:00
community-scripts-pr-app[bot]
0fba89af41 Update CHANGELOG.md (#17720)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 13:31:19 +00:00
community-scripts-pr-app[bot]
2fa0128614 Update CHANGELOG.md (#17719)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 13:24:53 +00:00
community-scripts-pr-app[bot]
efd8a86c2a Update CHANGELOG.md (#17718)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 13:23:14 +00:00
community-scripts-pr-app[bot]
c7257f3f9d Update CHANGELOG.md (#17717)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 11:40:22 +00:00
community-scripts-pr-app[bot]
15263edeaf Update CHANGELOG.md (#17716)
Some checks failed
Create Changelog Pull Request / update-changelog-pull-request (push) Has been cancelled
Set state to is_deleted in pocketbase / delete-pocketbase-entry (push) Has been cancelled
Sync ct/install to Incus / dispatch (push) Has been cancelled
Update script timestamp on .sh changes / update-script-timestamp (push) Has been cancelled
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 11:32:56 +00:00
community-scripts-pr-app[bot]
463d9828d9 Update CHANGELOG.md (#17715)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 11:32:35 +00:00
community-scripts-pr-app[bot]
405d2fa578 Update CHANGELOG.md (#17714)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 11:10:46 +00:00
community-scripts-pr-app[bot]
185ae4fde2 Update CHANGELOG.md (#17712)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 08:49:06 +00:00
push-app-to-main[bot]
bf3fad3984 Add pricebuddy (ct) (#17708)
Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
2026-10-06 10:48:36 +02:00
community-scripts-pr-app[bot]
10af1ac41f Update CHANGELOG.md (#17705)
Some checks failed
Create Changelog Pull Request / update-changelog-pull-request (push) Has been cancelled
Stale PR Management / stale-prs (push) Has been cancelled
Lock closed issues / lock (push) Has been cancelled
Create Daily Release / create-daily-release (push) Has been cancelled
Delete merged branches / delete-merged-branches (push) Has been cancelled
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-05 11:18:22 +00:00
community-scripts-pr-app[bot]
79e33e9fdc Update CHANGELOG.md (#17704)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-05 11:18:04 +00:00
community-scripts-pr-app[bot]
b87fe56bf0 Update CHANGELOG.md (#17703)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-05 11:14:42 +00:00
community-scripts-pr-app[bot]
0826ebad2a Update CHANGELOG.md (#17702)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-05 11:13:34 +00:00
community-scripts-pr-app[bot]
11c549ca4d Update CHANGELOG.md (#17701)
Some checks failed
Create Changelog Pull Request / update-changelog-pull-request (push) Has been cancelled
Set state to is_deleted in pocketbase / delete-pocketbase-entry (push) Has been cancelled
Sync ct/install to Incus / dispatch (push) Has been cancelled
Update script timestamp on .sh changes / update-script-timestamp (push) Has been cancelled
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-05 11:04:22 +00:00
community-scripts-pr-app[bot]
8ae3b842e4 Update CHANGELOG.md (#17700)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-05 10:48:56 +00:00
CanbiZ (MickLesk)
7d9648dc90 wanderer: set the proxy secret and install plugins in their own directories (#17698)
0.21 requires POCKETBASE_PROXY_SECRET on both services, or every
incoming federation request is rejected; both read the same .env.

Each plugin archive holds one directory, which the deploy strips, so all
three landed flat in plugins/ and overwrote each other. wanderer only
loads direct child directories, so it found none. Existing installs are
moved over on the next update.
2026-10-05 12:48:29 +02:00
community-scripts-pr-app[bot]
9d0b1e0354 Update CHANGELOG.md (#17699)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-05 10:48:08 +00:00
CanbiZ (MickLesk)
231b2fb1b7 discourse: serve stylesheets and repair the update (#17697)
nginx passed X-Accel-Mapping on every request. Stylesheets are sent
from tmp/, outside that mapping, so Rack redirected nginx to their
filesystem path and the page loaded without CSS. Existing installs get
the line removed on update.

The update called yarn, which is not installed, ran Rails without the
production environment or rbenv on PATH, asked for PostgreSQL 16 on a
17 install and left sidekiq running.
2026-10-05 12:47:42 +02:00
community-scripts-pr-app[bot]
e49cff4d54 Update CHANGELOG.md (#17696)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-05 09:03:34 +00:00
CanbiZ (MickLesk)
1c1295a9fd Point to DevScripts, the renamed ProxmoxVED (#17694)
Contribution docs, the PR template and the workflows that talk to the
testing repository use the new name. Migration PRs are matched by either
name, and three license headers pointed at contributor forks.
2026-10-05 11:03:02 +02:00
community-scripts-pr-app[bot]
ca6e8f407e Update CHANGELOG.md (#17695)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-05 08:40:08 +00:00
community-scripts-pr-app[bot]
e8a575dff4 Update CHANGELOG.md (#17692)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-05 06:50:51 +00:00
github-actions[bot]
5b5e8dc4f3 wikijs: bump Node.js from 24 to 26 (#17689)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-10-05 08:50:27 +02:00
community-scripts-pr-app[bot]
bcbe464ff9 Update CHANGELOG.md (#17691)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-05 06:47:58 +00:00
github-actions[bot]
7bde0ac8d9 jotty: bump Node.js from 22 to 24 (#17688)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-10-05 08:47:32 +02:00
community-scripts-pr-app[bot]
c225acc722 Update CHANGELOG.md (#17687)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-05 06:17:15 +00:00
Jason O'Brien
aaa341b6b2 monitor-all: read container IP from the host side (#17686)
The CT check resolved the IP by running ip inside the guest via pct
exec, which depends on the guest having it installed. If not, this
always comes back empty, so the container is restarted every cycle
despite answering ping. lxc-info reports the addresses from the
host without running anything inside the guest.

Fixes #17685
2026-10-05 08:16:45 +02:00
community-scripts-pr-app[bot]
1142165f73 Update CHANGELOG.md (#17683)
Some checks failed
Create Changelog Pull Request / update-changelog-pull-request (push) Has been cancelled
Set state to is_deleted in pocketbase / delete-pocketbase-entry (push) Has been cancelled
Sync ct/install to Incus / dispatch (push) Has been cancelled
Update script timestamp on .sh changes / update-script-timestamp (push) Has been cancelled
Stale PR Management / stale-prs (push) Has been cancelled
Lock closed issues / lock (push) Has been cancelled
Create Daily Release / create-daily-release (push) Has been cancelled
Delete merged branches / delete-merged-branches (push) Has been cancelled
Check Node.js Version Drift / check-node-versions (push) Has been cancelled
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-04 12:03:50 +00:00
CanbiZ (MickLesk)
63e2ce0849 immich: read the Intel runtime from the pinned release (#17677)
The URLs came from the ML Dockerfile on main, which upstream moved into
scripts/install-intel-runtime.sh, so update failed on the grep and
OpenVINO installs found no packages.
2026-10-04 14:03:24 +02:00
community-scripts-pr-app[bot]
2c33ecf7cf Update CHANGELOG.md (#17680)
Some checks failed
Create Changelog Pull Request / update-changelog-pull-request (push) Has been cancelled
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-04 09:45:56 +00:00
community-scripts-pr-app[bot]
22a5672945 Update CHANGELOG.md (#17679)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-04 09:45:31 +00:00
community-scripts-pr-app[bot]
bee57cc60f Update CHANGELOG.md (#17678)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-04 09:45:09 +00:00
115 changed files with 3642 additions and 3251 deletions

187
.github/changelogs/2026/10.md generated vendored
View File

@@ -1,3 +1,190 @@
## 2026-10-10
### 🆕 New Scripts
- Weblate ([#17837](https://github.com/community-scripts/ProxmoxVE/pull/17837))
- CertMate ([#17803](https://github.com/community-scripts/ProxmoxVE/pull/17803))
- AnythingLLM ([#17802](https://github.com/community-scripts/ProxmoxVE/pull/17802))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- update endurain repo from codeberg to gh [@johanngrobe](https://github.com/johanngrobe) ([#17831](https://github.com/community-scripts/ProxmoxVE/pull/17831))
- Immich: download countryInfo.txt into the geodata directory on update [@claytonfaria](https://github.com/claytonfaria) ([#17823](https://github.com/community-scripts/ProxmoxVE/pull/17823))
- paperclip: keep root and skip /opt/paperclip-data chown when PAPERCLIP_HOME is custom [@austinpilz](https://github.com/austinpilz) ([#17825](https://github.com/community-scripts/ProxmoxVE/pull/17825))
## 2026-10-09
### 🆕 New Scripts
- FoldingAtHome ([#17799](https://github.com/community-scripts/ProxmoxVE/pull/17799))
- LocalAI ([#17801](https://github.com/community-scripts/ProxmoxVE/pull/17801))
- Tvheadend ([#17800](https://github.com/community-scripts/ProxmoxVE/pull/17800))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- OpenCloud: fix Collabora embedding with Collabora 26.04.4 [@SimKaiLong](https://github.com/SimKaiLong) ([#17810](https://github.com/community-scripts/ProxmoxVE/pull/17810))
- #### 🔧 Refactor
- Immich: survive an interrupted update and a failing ML build [@MickLesk](https://github.com/MickLesk) ([#17798](https://github.com/community-scripts/ProxmoxVE/pull/17798))
### 💾 Core
- check_for_release: compare against the release marked as latest [@MickLesk](https://github.com/MickLesk) ([core#125](https://github.com/community-scripts/core/pull/125))
### 🧰 Tools
- #### ✨ New Features
- FileBrowser Quantum: migrate the config and database to v2 [@MickLesk](https://github.com/MickLesk) ([#17815](https://github.com/community-scripts/ProxmoxVE/pull/17815))
## 2026-10-08
### 🆕 New Scripts
- Unifi-OS-Server VM ([#17752](https://github.com/community-scripts/ProxmoxVE/pull/17752))
- ZimaOS VM ([#17778](https://github.com/community-scripts/ProxmoxVE/pull/17778))
### 🚀 Updated Scripts
- Revert "Immich: Pin to v3.3.0" [@MickLesk](https://github.com/MickLesk) ([#17767](https://github.com/community-scripts/ProxmoxVE/pull/17767))
- #### 🐞 Bug Fixes
- Homarr: replace the musl better-sqlite3 that v2.3.0 ships for Debian [@MickLesk](https://github.com/MickLesk) ([#17789](https://github.com/community-scripts/ProxmoxVE/pull/17789))
- CLIProxyAPI: keep plugins and data across updates [@MickLesk](https://github.com/MickLesk) ([#17790](https://github.com/community-scripts/ProxmoxVE/pull/17790))
- Kima-Hub: install the Python services into a uv venv [@MickLesk](https://github.com/MickLesk) ([#17791](https://github.com/community-scripts/ProxmoxVE/pull/17791))
- #### ✨ New Features
- Immich: Pin to 3.3.0 / Update ML Python to 3.13 [@MickLesk](https://github.com/MickLesk) ([#17770](https://github.com/community-scripts/ProxmoxVE/pull/17770))
- #### 🔧 Refactor
- Refactor: OPNsense VM [@MickLesk](https://github.com/MickLesk) ([#17785](https://github.com/community-scripts/ProxmoxVE/pull/17785))
- Refactor: Nextcloud VM (Turnkey) [@MickLesk](https://github.com/MickLesk) ([#17787](https://github.com/community-scripts/ProxmoxVE/pull/17787))
- Refactor: OpenWrt VM [@MickLesk](https://github.com/MickLesk) ([#17774](https://github.com/community-scripts/ProxmoxVE/pull/17774))
- Refactor: Ubuntu VM [@MickLesk](https://github.com/MickLesk) ([#17776](https://github.com/community-scripts/ProxmoxVE/pull/17776))
### 💾 Core
- Tolerate a missing datacenter.cfg in vm_keyboard_default [@MickLesk](https://github.com/MickLesk) ([core#124](https://github.com/community-scripts/core/pull/124))
- Take the ISO storage from the disk pool when it can hold ISOs [@MickLesk](https://github.com/MickLesk) ([core#122](https://github.com/community-scripts/core/pull/122))
- Shared VM helpers: disk import, releases, checksums, first boot, IP by MAC [@MickLesk](https://github.com/MickLesk) ([core#117](https://github.com/community-scripts/core/pull/117))
- tools: forge truncated release list [@MickLesk](https://github.com/MickLesk) ([core#118](https://github.com/community-scripts/core/pull/118))
- Remember a kept cached image until the upstream changes [@MickLesk](https://github.com/MickLesk) ([core#119](https://github.com/community-scripts/core/pull/119))
- Choose the VM keyboard layout and carry the host's timezone into prepared images [@MickLesk](https://github.com/MickLesk) ([core#120](https://github.com/community-scripts/core/pull/120))
- VM's: run first-boot units without debconf dialogs [@MickLesk](https://github.com/MickLesk) ([core#121](https://github.com/community-scripts/core/pull/121))
## 2026-10-07
### 🆕 New Scripts
- Fedora VM ([#17747](https://github.com/community-scripts/ProxmoxVE/pull/17747))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- AudioMuse-AI: replace the venv on update without asking [@MickLesk](https://github.com/MickLesk) ([#17738](https://github.com/community-scripts/ProxmoxVE/pull/17738))
- paperclip: run as a dedicated non-root user so Claude Code can skip permissions [@samvandenbossche](https://github.com/samvandenbossche) ([#17707](https://github.com/community-scripts/ProxmoxVE/pull/17707))
- Thingsboard: update Java version from 17 to 25 [@CerberusStyle](https://github.com/CerberusStyle) ([#17733](https://github.com/community-scripts/ProxmoxVE/pull/17733))
- #### ✨ New Features
- Immich: Pin to v3.3.0 [@vhsdream](https://github.com/vhsdream) ([#17759](https://github.com/community-scripts/ProxmoxVE/pull/17759))
- #### 💥 Breaking Changes
- OpenCloud: bump to v8.1.0, rebuild search index on upgrade [@SimKaiLong](https://github.com/SimKaiLong) ([#17710](https://github.com/community-scripts/ProxmoxVE/pull/17710))
- #### 🔧 Refactor
- Pangolin: Unpin Release, stable enough, Bump to latest [@MickLesk](https://github.com/MickLesk) ([#17740](https://github.com/community-scripts/ProxmoxVE/pull/17740))
- Refactor: Archlinux-VM [@MickLesk](https://github.com/MickLesk) ([#17741](https://github.com/community-scripts/ProxmoxVE/pull/17741))
- Refactor: MikroTik RouterOS [@MickLesk](https://github.com/MickLesk) ([#17748](https://github.com/community-scripts/ProxmoxVE/pull/17748))
### 💾 Core
- Fix Fedora and BLS cloud image console setup [@MickLesk](https://github.com/MickLesk) ([core#116](https://github.com/community-scripts/core/pull/116))
- Keep setup_nodejs alive when the caller's directory is gone [@MickLesk](https://github.com/MickLesk) ([core#114](https://github.com/community-scripts/core/pull/114))
## 2026-10-06
### 🆕 New Scripts
- Pricebuddy ([#17708](https://github.com/community-scripts/ProxmoxVE/pull/17708))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- Webtrees: stop serving data/ and the source folders directly [@MickLesk](https://github.com/MickLesk) ([#17724](https://github.com/community-scripts/ProxmoxVE/pull/17724))
### 💾 Core
- Incus: check the architecture on Incus hosts too [@MickLesk](https://github.com/MickLesk) ([core#113](https://github.com/community-scripts/core/pull/113))
- Incus: Pass the app's var_* settings into Incus containers [@MickLesk](https://github.com/MickLesk) ([core#112](https://github.com/community-scripts/core/pull/112))
- Incus: stub storage_content_check on Incus [@MickLesk](https://github.com/MickLesk) ([core#104](https://github.com/community-scripts/core/pull/104))
- Incus: map Proxmox template versions to Incus image names [@MickLesk](https://github.com/MickLesk) ([core#111](https://github.com/community-scripts/core/pull/111))
- Incus: read storage names from .vars files [@MickLesk](https://github.com/MickLesk) ([core#110](https://github.com/community-scripts/core/pull/110))
- Incus: show the spinner inside containers again [@MickLesk](https://github.com/MickLesk) ([core#109](https://github.com/community-scripts/core/pull/109))
- Incus: set the hostname with sh, so it works before bash is installed [@MickLesk](https://github.com/MickLesk) ([core#102](https://github.com/community-scripts/core/pull/102))
- Incus: reserve a plain address on Incus, leave the gateway to the network [@MickLesk](https://github.com/MickLesk) ([core#101](https://github.com/community-scripts/core/pull/101))
- Incus: Wait for the network on Alpine OS too [@MickLesk](https://github.com/MickLesk) ([core#105](https://github.com/community-scripts/core/pull/105))
- Incus: do not fail the build when hostname -I is missing [@MickLesk](https://github.com/MickLesk) ([core#103](https://github.com/community-scripts/core/pull/103))
- Incus: Fuse always in unprivileged Containers, attach TUN only when container lacks it [@MickLesk](https://github.com/MickLesk) ([core#108](https://github.com/community-scripts/core/pull/108))
- Incus: accept mode=generated [@MickLesk](https://github.com/MickLesk) ([core#106](https://github.com/community-scripts/core/pull/106))
- Incus: pass the full install environment into Incus containers (quoted) [@MickLesk](https://github.com/MickLesk) ([core#107](https://github.com/community-scripts/core/pull/107))
## 2026-10-05
### 🚀 Updated Scripts
- Point to DevScripts, the renamed ProxmoxVED [@MickLesk](https://github.com/MickLesk) ([#17694](https://github.com/community-scripts/ProxmoxVE/pull/17694))
- #### 🐞 Bug Fixes
- wanderer: set the proxy secret and install plugins in their own directories [@MickLesk](https://github.com/MickLesk) ([#17698](https://github.com/community-scripts/ProxmoxVE/pull/17698))
- discourse: serve stylesheets and repair the update [@MickLesk](https://github.com/MickLesk) ([#17697](https://github.com/community-scripts/ProxmoxVE/pull/17697))
- wikijs: bump Node.js from 24 to 26 [@github-actions[bot]](https://github.com/github-actions[bot]) ([#17689](https://github.com/community-scripts/ProxmoxVE/pull/17689))
- jotty: bump Node.js from 22 to 24 [@github-actions[bot]](https://github.com/github-actions[bot]) ([#17688](https://github.com/community-scripts/ProxmoxVE/pull/17688))
### 💾 Core
- Read releases from github.com when the API is rate limited, resume stalled downloads [@MickLesk](https://github.com/MickLesk) ([core#99](https://github.com/community-scripts/core/pull/99))
- Check for template and container storage before the settings menu [@MickLesk](https://github.com/MickLesk) ([core#98](https://github.com/community-scripts/core/pull/98))
- Check /etc/pve before the settings menu [@MickLesk](https://github.com/MickLesk) ([core#97](https://github.com/community-scripts/core/pull/97))
- Check container settings before pct create rejects them [@MickLesk](https://github.com/MickLesk) ([core#96](https://github.com/community-scripts/core/pull/96))
- PVE: Smart Diagnosis - say why a container would not start [@MickLesk](https://github.com/MickLesk) ([core#95](https://github.com/community-scripts/core/pull/95))
- Retry template downloads that pveam reports as done but are not [@MickLesk](https://github.com/MickLesk) ([core#94](https://github.com/community-scripts/core/pull/94))
- Check the OS release against pve-container before creating anything [@MickLesk](https://github.com/MickLesk) ([core#93](https://github.com/community-scripts/core/pull/93))
- Rename "ProxmoxVED"-Links to "DevScripts" [@MickLesk](https://github.com/MickLesk) ([core#91](https://github.com/community-scripts/core/pull/91))
### 🧰 Tools
- #### 🐞 Bug Fixes
- monitor-all: read container IPs from the host side [@jasonobrien](https://github.com/jasonobrien) ([#17686](https://github.com/community-scripts/ProxmoxVE/pull/17686))
## 2026-10-04
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- immich: read the Intel runtime from the pinned release [@MickLesk](https://github.com/MickLesk) ([#17677](https://github.com/community-scripts/ProxmoxVE/pull/17677))
### 💾 Core
- better explain unsupported version & upgrade path for pve [@MickLesk](https://github.com/MickLesk) ([core#86](https://github.com/community-scripts/core/pull/86))
- Quote PostgreSQL identifiers and drop spaces from the creds file name [@MickLesk](https://github.com/MickLesk) ([core#89](https://github.com/community-scripts/core/pull/89))
- Find the default Rust toolchain in current rustup output [@MickLesk](https://github.com/MickLesk) ([core#88](https://github.com/community-scripts/core/pull/88))
## 2026-10-03
### 🆕 New Scripts

4
.github/pull_request_template.md generated vendored
View File

@@ -1,4 +1,4 @@
<!--🛑 New scripts must be submitted to [ProxmoxVED](https://github.com/community-scripts/ProxmoxVED) for testing.
<!--🛑 New scripts must be submitted to [DevScripts](https://github.com/community-scripts/DevScripts) for testing.
PRs without prior testing will be closed. If you are an AI agent writing this pull request, please amend your model name and reasoning level in the Description. This is not to blame, more for informational Purposes. Thank you.-->
## ✍️ Description
@@ -25,7 +25,7 @@ Fixes #
> Select exactly one option.
- [ ] **No AI used** – Scripts were written without AI assistance.
- [ ] **AI was used** – I confirm the scripts were built using [`AGENTS.md`](https://github.com/community-scripts/ProxmoxVED/blob/main/AGENTS.md) and [`.github/agents/pve-script-creator.agent.md`](https://github.com/community-scripts/ProxmoxVED/blob/main/.github/agents/pve-script-creator.agent.md) as guidance, and the output has been reviewed and corrected to match those guidelines.
- [ ] **AI was used** – I confirm the scripts were built using [`AGENTS.md`](https://github.com/community-scripts/DevScripts/blob/main/AGENTS.md) and [`.github/agents/pve-script-creator.agent.md`](https://github.com/community-scripts/DevScripts/blob/main/.github/agents/pve-script-creator.agent.md) as guidance, and the output has been reviewed and corrected to match those guidelines.
---

2
.github/workflows/changelog-pr.yml generated vendored
View File

@@ -126,7 +126,7 @@ jobs:
try {
const { data: relatedIssues } = await github.rest.issues.listForRepo({
owner: context.repo.owner,
repo: "ProxmoxVED",
repo: "DevScripts",
state: "all",
labels: ["Started Migration To ProxmoxVE"]
});

View File

@@ -86,10 +86,10 @@ jobs:
``,
`However, **new scripts must first be submitted to our development repository** for testing and review before they can be merged here.`,
``,
`> 🛑 New scripts must be submitted to [**ProxmoxVED**](https://github.com/community-scripts/ProxmoxVED) for testing.`,
`> 🛑 New scripts must be submitted to [**DevScripts**](https://github.com/community-scripts/DevScripts) for testing.`,
`> PRs without prior testing will be closed.`,
``,
`Please open your PR at **https://github.com/community-scripts/ProxmoxVED** instead.`,
`Please open your PR at **https://github.com/community-scripts/DevScripts** instead.`,
`Once your script has been tested and approved there, it will be pushed to this repository automatically.`,
``,
`This PR will now be closed. Thank you for understanding! 🙏`,

View File

@@ -12,7 +12,7 @@ jobs:
if: github.event.pull_request.merged == true && github.repository == 'community-scripts/ProxmoxVE'
runs-on: self-hosted
env:
DEV_REPO: community-scripts/ProxmoxVED
DEV_REPO: community-scripts/DevScripts
steps:
- name: Checkout target repo (merge commit)
@@ -60,7 +60,7 @@ jobs:
echo "count=$(printf '%s' "$slugs" | wc -w | tr -d '[:space:]')" >> "$GITHUB_OUTPUT"
echo "Slugs in this PR: ${slugs:-<none>}"
- name: Resolve the matching ProxmoxVED issue
- name: Resolve the matching DevScripts issue
id: find_issue
shell: bash
env:
@@ -71,7 +71,7 @@ jobs:
# creates, so migration PRs carry an exact back-reference. Guessing from
# titles or file names is never needed for them.
matched=$(printf '%s' "$PR_BODY" \
| grep -oE 'community-scripts/ProxmoxVED#[0-9]+' \
| grep -oE 'community-scripts/(ProxmoxVED|DevScripts)#[0-9]+' \
| sed 's/.*#//' || true)
if [ -n "$matched" ]; then
@@ -96,7 +96,7 @@ jobs:
[ -n "$row" ] || continue
num=$(printf '%s' "$row" | jq -r '.number')
# Same slug derivation the ProxmoxVED workflows use, so both
# Same slug derivation the DevScripts workflows use, so both
# sides agree on what "alpine-cinny" means.
name=$(printf '%s' "$row" | jq -r '.body // ""' \
| sed -n '/^###[[:space:]]*Name of the Script/,/^###/p' \
@@ -124,7 +124,7 @@ jobs:
echo "issue_numbers=$matched" >> "$GITHUB_OUTPUT"
echo "Closing: ${matched:-<none>}"
- name: Comment on and close matching ProxmoxVED issues
- name: Comment on and close matching DevScripts issues
if: steps.find_issue.outputs.issue_numbers != ''
shell: bash
env:

View File

@@ -113,6 +113,9 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
@@ -126,7 +129,7 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
<details>
<summary><h4>October (3 entries)</h4></summary>
<summary><h4>October (10 entries)</h4></summary>
[View October 2026 Changelog](.github/changelogs/2026/10.md)
@@ -559,8 +562,221 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
</details>
## 2026-10-11
### 🆕 New Scripts
- Cinephage ([#17852](https://github.com/community-scripts/ProxmoxVE/pull/17852))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- hermesagent: match the relaunched root gateway regardless of interpreter [@MickLesk](https://github.com/MickLesk) ([#17847](https://github.com/community-scripts/ProxmoxVE/pull/17847))
- Radicale: install the bcrypt and argon2 extras [@MickLesk](https://github.com/MickLesk) ([#17813](https://github.com/community-scripts/ProxmoxVE/pull/17813))
- fix(zigbee2mqtt): preserve backup stream and prevent filename collisions [@petermnt](https://github.com/petermnt) ([#17751](https://github.com/community-scripts/ProxmoxVE/pull/17751))
- #### ✨ New Features
- QoL: let var_* answer the optional add-on prompts [@MickLesk](https://github.com/MickLesk) ([#17858](https://github.com/community-scripts/ProxmoxVE/pull/17858))
- QoL: Confirm third-party installers through confirm_external_installer [@MickLesk](https://github.com/MickLesk) ([#17857](https://github.com/community-scripts/ProxmoxVE/pull/17857))
- docker: take the lxcfs toggle, TCP socket and Compose choice from app variables [@MickLesk](https://github.com/MickLesk) ([#17850](https://github.com/community-scripts/ProxmoxVE/pull/17850))
### 💾 Core
- Add confirm_external_installer [@MickLesk](https://github.com/MickLesk) ([core#130](https://github.com/community-scripts/core/pull/130))
- setup_docker: make LXC resource limits visible to nested containers [@andrebrait](https://github.com/andrebrait) ([core#9](https://github.com/community-scripts/core/pull/9))
- Incus: fix ENABLE_FUSE / TUN vars [@MickLesk](https://github.com/MickLesk) ([core#127](https://github.com/community-scripts/core/pull/127))
- Resolve a uv required-version range to the newest release inside it [@MickLesk](https://github.com/MickLesk) ([core#126](https://github.com/community-scripts/core/pull/126))
- Upgrade MongoDB in place when an app package depends on it [@MickLesk](https://github.com/MickLesk) ([core#128](https://github.com/community-scripts/core/pull/128))
## 2026-10-10
### 🆕 New Scripts
- Weblate ([#17837](https://github.com/community-scripts/ProxmoxVE/pull/17837))
- CertMate ([#17803](https://github.com/community-scripts/ProxmoxVE/pull/17803))
- AnythingLLM ([#17802](https://github.com/community-scripts/ProxmoxVE/pull/17802))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- update endurain repo from codeberg to gh [@johanngrobe](https://github.com/johanngrobe) ([#17831](https://github.com/community-scripts/ProxmoxVE/pull/17831))
- Immich: download countryInfo.txt into the geodata directory on update [@claytonfaria](https://github.com/claytonfaria) ([#17823](https://github.com/community-scripts/ProxmoxVE/pull/17823))
- paperclip: keep root and skip /opt/paperclip-data chown when PAPERCLIP_HOME is custom [@austinpilz](https://github.com/austinpilz) ([#17825](https://github.com/community-scripts/ProxmoxVE/pull/17825))
## 2026-10-09
### 🆕 New Scripts
- FoldingAtHome ([#17799](https://github.com/community-scripts/ProxmoxVE/pull/17799))
- LocalAI ([#17801](https://github.com/community-scripts/ProxmoxVE/pull/17801))
- Tvheadend ([#17800](https://github.com/community-scripts/ProxmoxVE/pull/17800))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- OpenCloud: fix Collabora embedding with Collabora 26.04.4 [@SimKaiLong](https://github.com/SimKaiLong) ([#17810](https://github.com/community-scripts/ProxmoxVE/pull/17810))
- #### 🔧 Refactor
- Immich: survive an interrupted update and a failing ML build [@MickLesk](https://github.com/MickLesk) ([#17798](https://github.com/community-scripts/ProxmoxVE/pull/17798))
### 💾 Core
- check_for_release: compare against the release marked as latest [@MickLesk](https://github.com/MickLesk) ([core#125](https://github.com/community-scripts/core/pull/125))
### 🧰 Tools
- #### ✨ New Features
- FileBrowser Quantum: migrate the config and database to v2 [@MickLesk](https://github.com/MickLesk) ([#17815](https://github.com/community-scripts/ProxmoxVE/pull/17815))
## 2026-10-08
### 🆕 New Scripts
- Unifi-OS-Server VM ([#17752](https://github.com/community-scripts/ProxmoxVE/pull/17752))
- ZimaOS VM ([#17778](https://github.com/community-scripts/ProxmoxVE/pull/17778))
### 🚀 Updated Scripts
- Revert "Immich: Pin to v3.3.0" [@MickLesk](https://github.com/MickLesk) ([#17767](https://github.com/community-scripts/ProxmoxVE/pull/17767))
- #### 🐞 Bug Fixes
- Homarr: replace the musl better-sqlite3 that v2.3.0 ships for Debian [@MickLesk](https://github.com/MickLesk) ([#17789](https://github.com/community-scripts/ProxmoxVE/pull/17789))
- CLIProxyAPI: keep plugins and data across updates [@MickLesk](https://github.com/MickLesk) ([#17790](https://github.com/community-scripts/ProxmoxVE/pull/17790))
- Kima-Hub: install the Python services into a uv venv [@MickLesk](https://github.com/MickLesk) ([#17791](https://github.com/community-scripts/ProxmoxVE/pull/17791))
- #### ✨ New Features
- Immich: Pin to 3.3.0 / Update ML Python to 3.13 [@MickLesk](https://github.com/MickLesk) ([#17770](https://github.com/community-scripts/ProxmoxVE/pull/17770))
- #### 🔧 Refactor
- Refactor: OPNsense VM [@MickLesk](https://github.com/MickLesk) ([#17785](https://github.com/community-scripts/ProxmoxVE/pull/17785))
- Refactor: Nextcloud VM (Turnkey) [@MickLesk](https://github.com/MickLesk) ([#17787](https://github.com/community-scripts/ProxmoxVE/pull/17787))
- Refactor: OpenWrt VM [@MickLesk](https://github.com/MickLesk) ([#17774](https://github.com/community-scripts/ProxmoxVE/pull/17774))
- Refactor: Ubuntu VM [@MickLesk](https://github.com/MickLesk) ([#17776](https://github.com/community-scripts/ProxmoxVE/pull/17776))
### 💾 Core
- Tolerate a missing datacenter.cfg in vm_keyboard_default [@MickLesk](https://github.com/MickLesk) ([core#124](https://github.com/community-scripts/core/pull/124))
- Take the ISO storage from the disk pool when it can hold ISOs [@MickLesk](https://github.com/MickLesk) ([core#122](https://github.com/community-scripts/core/pull/122))
- Shared VM helpers: disk import, releases, checksums, first boot, IP by MAC [@MickLesk](https://github.com/MickLesk) ([core#117](https://github.com/community-scripts/core/pull/117))
- tools: forge truncated release list [@MickLesk](https://github.com/MickLesk) ([core#118](https://github.com/community-scripts/core/pull/118))
- Remember a kept cached image until the upstream changes [@MickLesk](https://github.com/MickLesk) ([core#119](https://github.com/community-scripts/core/pull/119))
- Choose the VM keyboard layout and carry the host's timezone into prepared images [@MickLesk](https://github.com/MickLesk) ([core#120](https://github.com/community-scripts/core/pull/120))
- VM's: run first-boot units without debconf dialogs [@MickLesk](https://github.com/MickLesk) ([core#121](https://github.com/community-scripts/core/pull/121))
## 2026-10-07
### 🆕 New Scripts
- Fedora VM ([#17747](https://github.com/community-scripts/ProxmoxVE/pull/17747))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- AudioMuse-AI: replace the venv on update without asking [@MickLesk](https://github.com/MickLesk) ([#17738](https://github.com/community-scripts/ProxmoxVE/pull/17738))
- paperclip: run as a dedicated non-root user so Claude Code can skip permissions [@samvandenbossche](https://github.com/samvandenbossche) ([#17707](https://github.com/community-scripts/ProxmoxVE/pull/17707))
- Thingsboard: update Java version from 17 to 25 [@CerberusStyle](https://github.com/CerberusStyle) ([#17733](https://github.com/community-scripts/ProxmoxVE/pull/17733))
- #### ✨ New Features
- Immich: Pin to v3.3.0 [@vhsdream](https://github.com/vhsdream) ([#17759](https://github.com/community-scripts/ProxmoxVE/pull/17759))
- #### 💥 Breaking Changes
- OpenCloud: bump to v8.1.0, rebuild search index on upgrade [@SimKaiLong](https://github.com/SimKaiLong) ([#17710](https://github.com/community-scripts/ProxmoxVE/pull/17710))
- #### 🔧 Refactor
- Pangolin: Unpin Release, stable enough, Bump to latest [@MickLesk](https://github.com/MickLesk) ([#17740](https://github.com/community-scripts/ProxmoxVE/pull/17740))
- Refactor: Archlinux-VM [@MickLesk](https://github.com/MickLesk) ([#17741](https://github.com/community-scripts/ProxmoxVE/pull/17741))
- Refactor: MikroTik RouterOS [@MickLesk](https://github.com/MickLesk) ([#17748](https://github.com/community-scripts/ProxmoxVE/pull/17748))
### 💾 Core
- Fix Fedora and BLS cloud image console setup [@MickLesk](https://github.com/MickLesk) ([core#116](https://github.com/community-scripts/core/pull/116))
- Keep setup_nodejs alive when the caller's directory is gone [@MickLesk](https://github.com/MickLesk) ([core#114](https://github.com/community-scripts/core/pull/114))
## 2026-10-06
### 🆕 New Scripts
- Pricebuddy ([#17708](https://github.com/community-scripts/ProxmoxVE/pull/17708))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- Webtrees: stop serving data/ and the source folders directly [@MickLesk](https://github.com/MickLesk) ([#17724](https://github.com/community-scripts/ProxmoxVE/pull/17724))
### 💾 Core
- Incus: check the architecture on Incus hosts too [@MickLesk](https://github.com/MickLesk) ([core#113](https://github.com/community-scripts/core/pull/113))
- Incus: Pass the app's var_* settings into Incus containers [@MickLesk](https://github.com/MickLesk) ([core#112](https://github.com/community-scripts/core/pull/112))
- Incus: stub storage_content_check on Incus [@MickLesk](https://github.com/MickLesk) ([core#104](https://github.com/community-scripts/core/pull/104))
- Incus: map Proxmox template versions to Incus image names [@MickLesk](https://github.com/MickLesk) ([core#111](https://github.com/community-scripts/core/pull/111))
- Incus: read storage names from .vars files [@MickLesk](https://github.com/MickLesk) ([core#110](https://github.com/community-scripts/core/pull/110))
- Incus: show the spinner inside containers again [@MickLesk](https://github.com/MickLesk) ([core#109](https://github.com/community-scripts/core/pull/109))
- Incus: set the hostname with sh, so it works before bash is installed [@MickLesk](https://github.com/MickLesk) ([core#102](https://github.com/community-scripts/core/pull/102))
- Incus: reserve a plain address on Incus, leave the gateway to the network [@MickLesk](https://github.com/MickLesk) ([core#101](https://github.com/community-scripts/core/pull/101))
- Incus: Wait for the network on Alpine OS too [@MickLesk](https://github.com/MickLesk) ([core#105](https://github.com/community-scripts/core/pull/105))
- Incus: do not fail the build when hostname -I is missing [@MickLesk](https://github.com/MickLesk) ([core#103](https://github.com/community-scripts/core/pull/103))
- Incus: Fuse always in unprivileged Containers, attach TUN only when container lacks it [@MickLesk](https://github.com/MickLesk) ([core#108](https://github.com/community-scripts/core/pull/108))
- Incus: accept mode=generated [@MickLesk](https://github.com/MickLesk) ([core#106](https://github.com/community-scripts/core/pull/106))
- Incus: pass the full install environment into Incus containers (quoted) [@MickLesk](https://github.com/MickLesk) ([core#107](https://github.com/community-scripts/core/pull/107))
## 2026-10-05
### 🚀 Updated Scripts
- Point to DevScripts, the renamed ProxmoxVED [@MickLesk](https://github.com/MickLesk) ([#17694](https://github.com/community-scripts/ProxmoxVE/pull/17694))
- #### 🐞 Bug Fixes
- wanderer: set the proxy secret and install plugins in their own directories [@MickLesk](https://github.com/MickLesk) ([#17698](https://github.com/community-scripts/ProxmoxVE/pull/17698))
- discourse: serve stylesheets and repair the update [@MickLesk](https://github.com/MickLesk) ([#17697](https://github.com/community-scripts/ProxmoxVE/pull/17697))
- wikijs: bump Node.js from 24 to 26 [@github-actions[bot]](https://github.com/github-actions[bot]) ([#17689](https://github.com/community-scripts/ProxmoxVE/pull/17689))
- jotty: bump Node.js from 22 to 24 [@github-actions[bot]](https://github.com/github-actions[bot]) ([#17688](https://github.com/community-scripts/ProxmoxVE/pull/17688))
### 💾 Core
- Read releases from github.com when the API is rate limited, resume stalled downloads [@MickLesk](https://github.com/MickLesk) ([core#99](https://github.com/community-scripts/core/pull/99))
- Check for template and container storage before the settings menu [@MickLesk](https://github.com/MickLesk) ([core#98](https://github.com/community-scripts/core/pull/98))
- Check /etc/pve before the settings menu [@MickLesk](https://github.com/MickLesk) ([core#97](https://github.com/community-scripts/core/pull/97))
- Check container settings before pct create rejects them [@MickLesk](https://github.com/MickLesk) ([core#96](https://github.com/community-scripts/core/pull/96))
- PVE: Smart Diagnosis - say why a container would not start [@MickLesk](https://github.com/MickLesk) ([core#95](https://github.com/community-scripts/core/pull/95))
- Retry template downloads that pveam reports as done but are not [@MickLesk](https://github.com/MickLesk) ([core#94](https://github.com/community-scripts/core/pull/94))
- Check the OS release against pve-container before creating anything [@MickLesk](https://github.com/MickLesk) ([core#93](https://github.com/community-scripts/core/pull/93))
- Rename "ProxmoxVED"-Links to "DevScripts" [@MickLesk](https://github.com/MickLesk) ([core#91](https://github.com/community-scripts/core/pull/91))
### 🧰 Tools
- #### 🐞 Bug Fixes
- monitor-all: read container IPs from the host side [@jasonobrien](https://github.com/jasonobrien) ([#17686](https://github.com/community-scripts/ProxmoxVE/pull/17686))
## 2026-10-04
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- immich: read the Intel runtime from the pinned release [@MickLesk](https://github.com/MickLesk) ([#17677](https://github.com/community-scripts/ProxmoxVE/pull/17677))
### 💾 Core
- better explain unsupported version & upgrade path for pve [@MickLesk](https://github.com/MickLesk) ([core#86](https://github.com/community-scripts/core/pull/86))
- Quote PostgreSQL identifiers and drop spaces from the creds file name [@MickLesk](https://github.com/MickLesk) ([core#89](https://github.com/community-scripts/core/pull/89))
- Find the default Rust toolchain in current rustup output [@MickLesk](https://github.com/MickLesk) ([core#88](https://github.com/community-scripts/core/pull/88))
## 2026-10-03
### 🆕 New Scripts
@@ -1085,145 +1301,4 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
### 📚 Documentation
- issue template: add PVE release, execution context and phase; refresh distro list / pve versions [@MickLesk](https://github.com/MickLesk) ([#17160](https://github.com/community-scripts/ProxmoxVE/pull/17160))
## 2026-09-10
### 🆕 New Scripts
- Chevereto ([#17131](https://github.com/community-scripts/ProxmoxVE/pull/17131))
- Portabase ([#17111](https://github.com/community-scripts/ProxmoxVE/pull/17111))
- Logseq ([#17112](https://github.com/community-scripts/ProxmoxVE/pull/17112))
- Safebucket ([#17096](https://github.com/community-scripts/ProxmoxVE/pull/17096))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- Immich v3.2.0 [@vhsdream](https://github.com/vhsdream) ([#17137](https://github.com/community-scripts/ProxmoxVE/pull/17137))
- fix(solidtime): prevent composer install from hanging on root prompt [@supersoju](https://github.com/supersoju) ([#17146](https://github.com/community-scripts/ProxmoxVE/pull/17146))
- fix(hermesagent): wait for root gateway cleanup [@steveonjava](https://github.com/steveonjava) ([#17147](https://github.com/community-scripts/ProxmoxVE/pull/17147))
### 💾 Core
- Keep the script name when regenerating the entrypoint [@MickLesk](https://github.com/MickLesk) ([core#35](https://github.com/community-scripts/core/pull/35))
- Rewrite the dead Gitea base onto GitHub instead of failing the update [@MickLesk](https://github.com/MickLesk) ([core#33](https://github.com/community-scripts/core/pull/33))
- core.func: fall back to a usable HOME when the shell has none [@MickLesk](https://github.com/MickLesk) ([core#32](https://github.com/community-scripts/core/pull/32))
## 2026-09-09
### 🆕 New Scripts
- Lingarr ([#17130](https://github.com/community-scripts/ProxmoxVE/pull/17130))
### 🚀 Updated Scripts
- vm: drop the discussions link from the summary [@MickLesk](https://github.com/MickLesk) ([#17117](https://github.com/community-scripts/ProxmoxVE/pull/17117))
- #### 🐞 Bug Fixes
- fix(hermesagent): stop spurious root gateway after update [@steveonjava](https://github.com/steveonjava) ([#17126](https://github.com/community-scripts/ProxmoxVE/pull/17126))
## 2026-09-08
### 🆕 New Scripts
- Decypharr ([#17108](https://github.com/community-scripts/ProxmoxVE/pull/17108))
- Stash ([#17106](https://github.com/community-scripts/ProxmoxVE/pull/17106))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- Update Jellyfin FFmpeg dependency to version 8 [@MickLesk](https://github.com/MickLesk) ([#17109](https://github.com/community-scripts/ProxmoxVE/pull/17109))
### 💾 Core
- Treat a cut-short forge response as a failure, not as HTTP 200 [@MickLesk](https://github.com/MickLesk) ([core#31](https://github.com/community-scripts/core/pull/31))
- Generate app headers [@github-actions[bot]](https://github.com/github-actions[bot]) ([core#28](https://github.com/community-scripts/core/pull/28))
- cloud-init: drop the "configure in Proxmox UI" hint [@MickLesk](https://github.com/MickLesk) ([core#30](https://github.com/community-scripts/core/pull/30))
- Survive an empty /usr/bin/update instead of aborting the run [@MickLesk](https://github.com/MickLesk) ([core#29](https://github.com/community-scripts/core/pull/29))
## 2026-09-07
### 🆕 New Scripts
- Chatwoot ([#17095](https://github.com/community-scripts/ProxmoxVE/pull/17095))
- whisparr-eros ([#17094](https://github.com/community-scripts/ProxmoxVE/pull/17094))
- Matter-Hub ([#17093](https://github.com/community-scripts/ProxmoxVE/pull/17093))
- Journiv ([#17092](https://github.com/community-scripts/ProxmoxVE/pull/17092))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- kaneo: bump Node.js from 22 to 24 [@github-actions[bot]](https://github.com/github-actions[bot]) ([#17086](https://github.com/community-scripts/ProxmoxVE/pull/17086))
- iobroker: bump Node.js from 24 to 26 [@github-actions[bot]](https://github.com/github-actions[bot]) ([#17085](https://github.com/community-scripts/ProxmoxVE/pull/17085))
- reactive-resume: repair any wrong WorkingDirectory on update [@MickLesk](https://github.com/MickLesk) ([#17068](https://github.com/community-scripts/ProxmoxVE/pull/17068))
- mediamtx: keep mediamtx.yml across updates [@MickLesk](https://github.com/MickLesk) ([#17069](https://github.com/community-scripts/ProxmoxVE/pull/17069))
- omnitools: allow remote action while npm ci [@MickLesk](https://github.com/MickLesk) ([#17070](https://github.com/community-scripts/ProxmoxVE/pull/17070))
- #### ✨ New Features
- netboot-xyz: add Secure Boot and Legacy assets [@MickLesk](https://github.com/MickLesk) ([#17066](https://github.com/community-scripts/ProxmoxVE/pull/17066))
- #### 🔧 Refactor
- flatnotes: follow upstream move to uv and Python 3.13 [@MickLesk](https://github.com/MickLesk) ([#17090](https://github.com/community-scripts/ProxmoxVE/pull/17090))
- heimdall: set up PHP 8.4 on update, keep only the database, run migrations [@MickLesk](https://github.com/MickLesk) ([#17067](https://github.com/community-scripts/ProxmoxVE/pull/17067))
### 📂 Github
- github: Open per-script Node bump PRs [@MickLesk](https://github.com/MickLesk) ([#17065](https://github.com/community-scripts/ProxmoxVE/pull/17065))
## 2026-09-06
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- Fix Sonarqube update script to add +x on sonar.sh [@jarihu](https://github.com/jarihu) ([#17056](https://github.com/community-scripts/ProxmoxVE/pull/17056))
## 2026-09-05
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- authentik: scope blueprints chown to avoid recursing into the mp0 bind mount [@MickLesk](https://github.com/MickLesk) ([#17008](https://github.com/community-scripts/ProxmoxVE/pull/17008))
- iventoy: run iventoy.sh with bash instead of dash [@MickLesk](https://github.com/MickLesk) ([#17034](https://github.com/community-scripts/ProxmoxVE/pull/17034))
- frigate: restart go2rtc.service before frigate starts [@MickLesk](https://github.com/MickLesk) ([#17035](https://github.com/community-scripts/ProxmoxVE/pull/17035))
- snapotter: seed AI venv base packages on arm64, warn amd64 has no working CPU bundle [@MickLesk](https://github.com/MickLesk) ([#16903](https://github.com/community-scripts/ProxmoxVE/pull/16903))
- tolgee: bump required JDK from 21 to 25 [@MickLesk](https://github.com/MickLesk) ([#17005](https://github.com/community-scripts/ProxmoxVE/pull/17005))
- romm: write real version into backend/__version__.py placeholder [@MickLesk](https://github.com/MickLesk) ([#17009](https://github.com/community-scripts/ProxmoxVE/pull/17009))
- #### 🔧 Refactor
- Refactor FileFlows: Stop Spinner before read -rp / Switch from "Node" to "Agent" [@MickLesk](https://github.com/MickLesk) ([#17007](https://github.com/community-scripts/ProxmoxVE/pull/17007))
### 💾 Core
- update helper: follow renamed ct/ scripts instead of curling a 404 [@MickLesk](https://github.com/MickLesk) ([core#22](https://github.com/community-scripts/core/pull/22))
- Use Proxmox for a template before reaching for linuxcontainers.org [@MickLesk](https://github.com/MickLesk) ([core#23](https://github.com/community-scripts/core/pull/23))
- implement exponential backoff for curl retries in _cs_curl_retry function [@MickLesk](https://github.com/MickLesk) ([core#26](https://github.com/community-scripts/core/pull/26))
### 🧰 Tools
- #### 🐞 Bug Fixes
- update-apps: follow renamed ct/ scripts instead of erroring out [@MickLesk](https://github.com/MickLesk) ([#16991](https://github.com/community-scripts/ProxmoxVE/pull/16991))
## 2026-09-04
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- fix(shlink): preserve servers.json across web-client updates [@Corgei](https://github.com/Corgei) ([#17023](https://github.com/community-scripts/ProxmoxVE/pull/17023))
- fix-update-authentik-2026.8.1 [@thieneret](https://github.com/thieneret) ([#16999](https://github.com/community-scripts/ProxmoxVE/pull/16999))
- Fix npm v12 allow-git/allow-remote restrictions across affected scripts [@MickLesk](https://github.com/MickLesk) ([#17014](https://github.com/community-scripts/ProxmoxVE/pull/17014))
- Fix/poznote - 1st party Docker parity [@lucas-at-3x-eye](https://github.com/lucas-at-3x-eye) ([#17011](https://github.com/community-scripts/ProxmoxVE/pull/17011))
### 💾 Core
- setup_go: resolve bare major.minor versions to the latest patch release [@MickLesk](https://github.com/MickLesk) ([core#24](https://github.com/community-scripts/core/pull/24))
- issue template: add PVE release, execution context and phase; refresh distro list / pve versions [@MickLesk](https://github.com/MickLesk) ([#17160](https://github.com/community-scripts/ProxmoxVE/pull/17160))

View File

@@ -9,13 +9,13 @@ For detailed coding standards and full documentation, visit **[community-scripts
## How Can I Help?
> [!IMPORTANT]
> **New scripts** must always be submitted to [ProxmoxVED](https://github.com/community-scripts/ProxmoxVED) first — not to this repository.
> **New scripts** must always be submitted to [DevScripts](https://github.com/community-scripts/DevScripts) first — not to this repository.
> PRs with new scripts opened directly against ProxmoxVE **will be closed without review**.
> **Bug fixes, improvements, and features for existing scripts** go here (ProxmoxVE).
| I want to… | Where to go |
| :------------------------------------------ | :------------------------------------------------------------------------------------------- |
| **Add a brand-new script** | [ProxmoxVED](https://github.com/community-scripts/ProxmoxVED) — testing repo for new scripts |
| **Add a brand-new script** | [DevScripts](https://github.com/community-scripts/DevScripts) — testing repo for new scripts |
| **Fix a bug or improve an existing script** | This repo (ProxmoxVE) — open a PR here |
| **Add a feature to an existing script** | This repo (ProxmoxVE) — open a PR here |
| Report a bug or broken script | [Open an Issue](https://github.com/community-scripts/ProxmoxVE/issues) |
@@ -55,13 +55,13 @@ Use existing scripts in [`ct/`](ct/) and [`install/`](install/) as reference. Fu
New scripts are **not accepted directly in this repository**. The workflow is:
1. Fork [ProxmoxVED](https://github.com/community-scripts/ProxmoxVED) and clone it
1. Fork [DevScripts](https://github.com/community-scripts/DevScripts) and clone it
2. Create a branch: `git switch -c feat/myapp`
3. Write your two script files:
- `ct/myapp.sh`
- `install/myapp-install.sh`
4. Test thoroughly in ProxmoxVED — run the script against a real Proxmox instance
5. Open a PR in **ProxmoxVED** for review and testing
4. Test thoroughly in DevScripts — run the script against a real Proxmox instance
5. Open a PR in **DevScripts** for review and testing
6. Once accepted and verified there, the script will be promoted to ProxmoxVE by maintainers
Follow the coding standards at [community-scripts.org/docs/contribution](https://community-scripts.org/docs/contribution).
@@ -193,5 +193,5 @@ create` still ran and the container was still built.
- **Website metadata** (name, description, logo, tags) is managed via the website — use the "Report Issue" link on any script page to request changes. Do not submit metadata changes via repo files.
- **JSON files** in `json/` define script properties used by the website. See existing files for structure reference.
- Keep PRs small and focused. One fix or feature per PR is ideal.
- PRs with **new scripts** opened against ProxmoxVE will be closed — submit them to [ProxmoxVED](https://github.com/community-scripts/ProxmoxVED) instead.
- PRs with **new scripts** opened against ProxmoxVE will be closed — submit them to [DevScripts](https://github.com/community-scripts/DevScripts) instead.
- PRs that fail CI checks will not be merged.

View File

@@ -93,7 +93,7 @@ This project runs on community contributions. Whether you want to write new scri
| I want to… | Go here |
| ------------------------------------- | ------------------------------------------------------------------------------------------------- |
| Add a **new** script | [ProxmoxVED](https://github.com/community-scripts/ProxmoxVED) — new scripts are tested here first |
| Add a **new** script | [DevScripts](https://github.com/community-scripts/DevScripts) — new scripts are tested here first |
| Fix or improve an **existing** script | [Contributing Guidelines](CONTRIBUTING.md) — open a PR in this repo |
| Report a bug or broken script | [Issues](https://github.com/community-scripts/ProxmoxVE/issues) |
| Request a new script or feature | [Discussions](https://github.com/community-scripts/ProxmoxVE/discussions) |
@@ -102,7 +102,7 @@ This project runs on community contributions. Whether you want to write new scri
### Before you open a PR
- **New scripts go to [ProxmoxVED](https://github.com/community-scripts/ProxmoxVED), not here.** PRs with new scripts opened directly against this repo will be closed.
- **New scripts go to [DevScripts](https://github.com/community-scripts/DevScripts), not here.** PRs with new scripts opened directly against this repo will be closed.
- Bug fixes and improvements to existing scripts belong in this repo — read the [Contributing Guidelines](CONTRIBUTING.md) first.
- Keep PRs focused. One fix or feature per PR.
- Document what your script installs and any non-obvious decisions in the corresponding JSON metadata file.

78
ct/anythingllm.sh Normal file
View File

@@ -0,0 +1,78 @@
#!/usr/bin/env bash
# Engine comes from community-scripts/core; this repo only ships the scripts.
# A local core checkout wins (COMMUNITY_SCRIPTS_CORE_DIR, else a sibling ../core),
# so a fork or branch of core can be tested without editing this file.
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/Mintplex-Labs/anything-llm
APP="AnythingLLM"
var_tags="${var_tags:-ai;rag}"
var_cpu="${var_cpu:-4}"
var_ram="${var_ram:-6144}"
var_disk="${var_disk:-20}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_gpu="${var_gpu:-yes}"
#var_arm64="${var_arm64:-no}" # unset = ask the user; set yes/no only when verified
var_unprivileged="${var_unprivileged:-1}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -d /opt/anythingllm ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "anythingllm" "Mintplex-Labs/anything-llm"; then
msg_info "Stopping Services"
systemctl stop anythingllm anythingllm-collector
msg_ok "Stopped Services"
create_backup /opt/anythingllm/server/.env /opt/anythingllm/collector/.env /opt/anythingllm/frontend/.env
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "anythingllm" "Mintplex-Labs/anything-llm" "tarball"
restore_backup
msg_info "Building AnythingLLM (Patience)"
cd /opt/anythingllm
export PUPPETEER_SKIP_DOWNLOAD=true
export NODE_OPTIONS="--max-old-space-size=3072"
$STD yarn setup
cd /opt/anythingllm/frontend
$STD yarn build
rm -rf /opt/anythingllm/server/public
cp -R /opt/anythingllm/frontend/dist /opt/anythingllm/server/public
cd /opt/anythingllm/server
$STD npx prisma generate --schema=./prisma/schema.prisma
$STD npx prisma migrate deploy --schema=./prisma/schema.prisma
msg_ok "Built AnythingLLM"
msg_info "Starting Services"
systemctl start anythingllm anythingllm-collector
msg_ok "Started Services"
msg_ok "Updated successfully!"
fi
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}:3001${CL}"

View File

@@ -58,7 +58,7 @@ function update_script() {
msg_info "Updating Python Environment (${AUDIOMUSE_BACKEND})"
cd /opt/audiomuse-ai
$STD uv venv --seed --python "$PY_VERSION" /opt/audiomuse-ai/.venv
$STD uv venv --clear --seed --python "$PY_VERSION" /opt/audiomuse-ai/.venv
$STD uv pip install --python /opt/audiomuse-ai/.venv \
-r "/opt/audiomuse-ai/requirements/${REQ_COMMON}" \
-r "/opt/audiomuse-ai/requirements/${REQ_ACCEL}"

View File

@@ -48,7 +48,12 @@ function update_script() {
$STD corepack prepare "pnpm@${PNPM_VERSION}" --activate
$STD pnpm install --frozen-lockfile
$STD pnpm --filter client run build-only
# vite's bundler (rolldown) crashes at random on some builds, rolldown#10860.
for attempt in 1 2 3; do
$STD pnpm --filter client run build-only && break
[[ $attempt -eq 3 ]] && { msg_error "Client build failed three times"; exit 1; }
msg_warn "Client build failed (attempt $attempt), retrying"
done
$STD pnpm --filter server run build
cp -r /opt/bookorbit/client/dist /opt/bookorbit/server/public
mkdir -p /opt/bookorbit/server/migrations

View File

@@ -38,11 +38,18 @@ update_deb_based() {
exit
fi
cleanup_old_repo_files "caddy"
msg_info "Updating Caddy LXC"
apt_update_safe
$STD apt upgrade -y
msg_ok "Updated Caddy LXC"
[[ -f ~/.caddy ]] || dpkg-query -W -f='${Version}' caddy >~/.caddy 2>/dev/null || true
if check_for_gh_release "caddy" "caddyserver/caddy"; then
DPKG_FORCE_CONFOLD=1 fetch_and_deploy_gh_release "caddy" "caddyserver/caddy" "binary" "latest" "/opt/caddy" "caddy_*_linux_$(arch_resolve).deb"
systemctl restart caddy
fi
if command -v xcaddy >/dev/null 2>&1; then
if check_for_gh_release "xcaddy" "caddyserver/xcaddy"; then
setup_go

65
ct/certmate.sh Normal file
View File

@@ -0,0 +1,65 @@
#!/usr/bin/env bash
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: fabriziosalmi
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/fabriziosalmi/certmate
APP="CertMate"
var_tags="${var_tags:-ssl;certificates;acme}"
var_cpu="${var_cpu:-2}"
var_ram="${var_ram:-2048}"
var_disk="${var_disk:-8}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
#var_arm64="${var_arm64:-no}" # unset = ask the user; set yes/no only when verified
var_unprivileged="${var_unprivileged:-1}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -d /opt/certmate ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "certmate" "fabriziosalmi/certmate"; then
msg_info "Stopping CertMate"
systemctl stop certmate
msg_ok "Stopped CertMate"
PYTHON_VERSION="3.12" setup_uv
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "certmate" "fabriziosalmi/certmate" "tarball"
msg_info "Installing CertMate Dependencies"
cd /opt/certmate
$STD uv venv --python 3.12 /opt/certmate/.venv
$STD uv pip sync --python /opt/certmate/.venv/bin/python requirements.lock
$STD /opt/certmate/.venv/bin/certbot --version
msg_ok "Installed CertMate Dependencies"
msg_info "Starting CertMate"
systemctl start certmate
msg_ok "Started CertMate"
msg_ok "Updated successfully!"
fi
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}:8000${CL}"
echo -e "${INFO}${YW}The first page creates the admin account and asks for the API token: grep API_BEARER_TOKEN /opt/certmate_data/.env${CL}"

69
ct/cinephage.sh Normal file
View File

@@ -0,0 +1,69 @@
#!/usr/bin/env bash
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/MoldyTaint/Cinephage
APP="Cinephage"
var_tags="${var_tags:-arr;media;torrent;usenet}"
var_cpu="${var_cpu:-2}"
var_ram="${var_ram:-4096}"
var_disk="${var_disk:-10}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-yes}"
var_unprivileged="${var_unprivileged:-1}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -d /opt/cinephage ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "cinephage" "MoldyTaint/Cinephage"; then
msg_info "Stopping Cinephage"
systemctl stop cinephage
msg_ok "Stopped Cinephage"
NODE_VERSION="24" setup_nodejs
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "cinephage" "MoldyTaint/Cinephage" "tarball"
msg_info "Building Cinephage"
cd /opt/cinephage
$STD npm ci
$STD npm run build
$STD npm prune --omit=dev
sed -i "s/^APP_VERSION=.*/APP_VERSION=$(cat ~/.cinephage)/" /opt/cinephage_data/.env
msg_ok "Built Cinephage"
msg_info "Updating Camoufox"
$STD /opt/cinephage/node_modules/.bin/camoufox-js fetch
msg_ok "Updated Camoufox"
msg_info "Starting Cinephage"
systemctl start cinephage
msg_ok "Started Cinephage"
msg_ok "Updated successfully!"
fi
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}:3000${CL}"

View File

@@ -39,7 +39,7 @@ function update_script() {
create_backup /opt/cliproxyapi/config.yaml
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "cliproxyapi" "router-for-me/CLIProxyAPI" "prebuild" "latest" "/opt/cliproxyapi" "CLIProxyAPI_*_linux_$(arch_resolve "amd64" "aarch64").tar.gz"
CLEAN_INSTALL=1 CLEAN_INSTALL_KEEP="plugins data" fetch_and_deploy_gh_release "cliproxyapi" "router-for-me/CLIProxyAPI" "prebuild" "latest" "/opt/cliproxyapi" "CLIProxyAPI_*_linux_$(arch_resolve "amd64" "aarch64").tar.gz"
restore_backup

View File

@@ -36,28 +36,35 @@ function update_script() {
exit
fi
msg_info "Stopping Service"
systemctl stop discourse
msg_ok "Stopped Service"
if grep -q 'X-Accel-Mapping' /etc/nginx/sites-available/discourse 2>/dev/null; then
msg_info "Fixing stylesheet delivery in Nginx"
sed -i '/X-Accel-Mapping/d' /etc/nginx/sites-available/discourse
$STD systemctl reload nginx
msg_ok "Fixed stylesheet delivery in Nginx"
fi
create_backup /opt/discourse/.env
msg_info "Stopping Services"
systemctl stop discourse discourse-sidekiq
msg_ok "Stopped Services"
msg_info "Updating Discourse"
PG_VERSION="16" PG_MODULES="pgvector" setup_postgresql
cd /opt/discourse
git pull origin main
$STD bundle install --deployment --without test development
$STD yarn install
export PATH="$HOME/.rbenv/bin:$HOME/.rbenv/shims:$PATH"
export COREPACK_ENABLE_DOWNLOAD_PROMPT=0
set -a
source /opt/discourse/.env
set +a
$STD git pull origin main
$STD bundle install
$STD pnpm install
$STD runuser -u postgres -- psql -d discourse -c "CREATE EXTENSION IF NOT EXISTS vector;"
$STD bundle exec rails assets:precompile
$STD bundle exec rails db:migrate
$STD bundle exec rails assets:precompile
msg_ok "Updated Discourse"
restore_backup
msg_info "Starting Service"
systemctl start discourse
msg_ok "Started Service"
msg_info "Starting Services"
systemctl start discourse discourse-sidekiq
msg_ok "Started Services"
msg_ok "Updated successfully!"
exit
}

View File

@@ -27,6 +27,10 @@ else
var_disk="${var_disk:-4}"
var_version="${var_version:-13}"
fi
# Only exported variables reach the install through lxc-attach.
export var_docker_socket="${var_docker_socket:-}"
export var_docker_compose="${var_docker_compose:-}"
export var_docker_lxcfs="${var_docker_lxcfs:-}"
header_info "$APP"
variables

View File

@@ -30,14 +30,14 @@ function update_script() {
msg_error "No ${APP} installation found!"
exit 233
fi
if check_for_codeberg_release "endurain" "endurain-project/endurain"; then
if check_for_gh_release "endurain" "endurain-project/endurain"; then
msg_info "Stopping Service"
systemctl stop endurain
msg_ok "Stopped Service"
NODE_VERSION="24" setup_nodejs
create_backup /opt/endurain/.env /opt/endurain/frontend/dist/env.js
CLEAN_INSTALL=1 fetch_and_deploy_codeberg_release "endurain" "endurain-project/endurain" "tarball" "latest" "/opt/endurain"
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "endurain" "endurain-project/endurain"
msg_info "Updating Endurain Frontend"
cd /opt/endurain

52
ct/foldingathome.sh Normal file
View File

@@ -0,0 +1,52 @@
#!/usr/bin/env bash
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ) | Co-Author: 007hacky007
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/FoldingAtHome/fah-client-bastet
APP="FoldingAtHome"
var_tags="${var_tags:-science;distributed-computing}"
var_cpu="${var_cpu:-4}"
var_ram="${var_ram:-2048}"
var_disk="${var_disk:-8}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-yes}"
var_gpu="${var_gpu:-yes}"
var_unprivileged="${var_unprivileged:-1}"
export var_fah_token="${var_fah_token:-}"
export var_fah_machine_name="${var_fah_machine_name:-}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -f /usr/bin/fah-client ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
fetch_and_deploy_from_url "https://download.foldingathome.org/releases/public/fah-client/$(arch_resolve "debian-10-64bit" "debian-stable-arm64")/release/latest.deb"
msg_ok "Folding@home is at $(dpkg-query -W -f='${Version}' fah-client)"
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Manage it from the Folding@home Web Control:${CL}"
echo -e "${GATEWAY}${BGN}https://app.foldingathome.org/${CL}"
echo -e "${INFO}${YW}The client starts paused - press Fold once the machine shows up in your account${CL}"
echo -e "${INFO}${YW}Account token and machine name are in /etc/fah-client/config.xml${CL}"

View File

@@ -31,16 +31,7 @@ function update_script() {
exit
fi
msg_warn "WARNING: This script will run an external installer from a third-party source (https://hermes-agent.nousresearch.com/)."
msg_warn "The following code is NOT maintained or audited by our repository."
msg_warn "If you have any doubts or concerns, please review the installer code before proceeding:"
msg_custom "${TAB3}${GATEWAY}${BGN}${CL}" "\e[1;34m" "→ hermes update (https://hermes-agent.nousresearch.com/)"
echo
read -r -p "${TAB3}Do you want to continue? [y/N]: " CONFIRM
if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
msg_error "Aborted by user. No changes have been made."
exit 10
fi
confirm_external_installer "https://hermes-agent.nousresearch.com/" "hermes update (https://hermes-agent.nousresearch.com/)"
msg_info "Stopping Services"
systemctl stop hermes-dashboard
@@ -51,8 +42,7 @@ function update_script() {
set -a; source /etc/default/hermes; set +a
/home/hermes/.local/bin/hermes update --yes
'
# See https://github.com/community-scripts/ProxmoxVE/issues/17123
mapfile -t root_gateway_pids < <(ps -eo user=,pid=,args= | awk '$1 == "root" && $0 ~ /\/home\/hermes\/\.hermes\/hermes-agent\/venv\/bin\/python -m hermes_cli\.main gateway run --replace$/ { print $2 }')
mapfile -t root_gateway_pids < <(ps -eo user=,pid=,args= | awk '$1 == "root" && /\/home\/hermes\/\.hermes\// && /hermes_cli[.]main/ && / gateway run --replace$/ { print $2 }')
if ((${#root_gateway_pids[@]})); then
kill -TERM "${root_gateway_pids[@]}"
for pid in "${root_gateway_pids[@]}"; do
@@ -61,7 +51,14 @@ function update_script() {
done
done
fi
chown -R hermes:hermes /home/hermes
if ps -eo user=,args= | awk '$1 == "root" && /\/home\/hermes\/\.hermes\// { found = 1 } END { exit !found }'; then
msg_warn "A root-owned Hermes process is still running; it may keep writing root-owned files"
fi
# A writer racing chown makes files vanish between readdir and chown; one retry covers it.
if ! chown -R hermes:hermes /home/hermes 2>/dev/null; then
sleep 1
chown -R hermes:hermes /home/hermes || msg_warn "Could not take ownership of everything under /home/hermes"
fi
msg_ok "Updated Hermes Agent"
msg_info "Starting Services"

View File

@@ -85,6 +85,18 @@ EOF
msg_ok "Started Services"
msg_ok "Updated successfully!"
fi
# v2.3.0's Debian build ships a musl better-sqlite3 (homarr-labs/homarr#7097).
mapfile -t MUSL_MODULES < <(find /opt/homarr -name better_sqlite3.node -exec grep -aqE "ld-musl|libc\.musl" {} \; -print)
if ((${#MUSL_MODULES[@]})); then
msg_info "Replacing musl better-sqlite3 build"
BSQ_VERSION=$(jq -r .version /opt/homarr/node_modules/better-sqlite3/package.json)
curl_with_retry "https://github.com/WiseLibs/better-sqlite3/releases/download/v${BSQ_VERSION}/better-sqlite3-v${BSQ_VERSION}-node-v$(node -p process.versions.modules)-linux-$(arch_resolve "x64" "arm64").tar.gz" /tmp/better-sqlite3.tar.gz
tar -xzf /tmp/better-sqlite3.tar.gz -C /tmp build/Release/better_sqlite3.node
for module in "${MUSL_MODULES[@]}"; do cp /tmp/build/Release/better_sqlite3.node "$module"; done
rm -rf /tmp/better-sqlite3.tar.gz /tmp/build
systemctl restart homarr
msg_ok "Replaced musl better-sqlite3 build"
fi
exit
}

View File

@@ -77,14 +77,17 @@ EOF
BASE_DIR=${STAGING_DIR}/base-images
SOURCE_DIR=${STAGING_DIR}/image-source
cd /tmp
RELEASE="v3.3.0"
if [[ -f ~/.intel_version ]]; then
curl_with_retry "https://raw.githubusercontent.com/immich-app/immich/refs/heads/main/machine-learning/Dockerfile" "Dockerfile"
readarray -t INTEL_URLS < <(
sed -n "/intel-[igc|opencl]/p" ./Dockerfile | awk '{print $3}'
sed -n "/libigdgmm12/p" ./Dockerfile | awk '{print $3}'
)
INTEL_RELEASE="$(grep "intel-opencl-icd_" ./Dockerfile | awk -F '_' '{print $2}')"
if [[ "$INTEL_RELEASE" != "$(cat ~/.intel_version)" ]]; then
INTEL_SRC="https://raw.githubusercontent.com/immich-app/immich/${RELEASE}/machine-learning"
curl -fsSL "${INTEL_SRC}/scripts/install-intel-runtime.sh" -o ./intel-runtime 2>/dev/null ||
curl_with_retry "${INTEL_SRC}/Dockerfile" "./intel-runtime"
readarray -t INTEL_URLS < <(grep -oE 'https://github\.com/intel/[^[:space:]]+\.deb' ./intel-runtime)
INTEL_RELEASE="$(grep -oE 'intel-opencl-icd_[^_]+' ./intel-runtime | cut -d_ -f2)" || true
rm -f ./intel-runtime
if [[ -z "$INTEL_RELEASE" ]]; then
msg_warn "No Intel runtime found for Immich ${RELEASE}, keeping the installed one"
elif [[ "$INTEL_RELEASE" != "$(cat ~/.intel_version)" ]]; then
msg_info "Updating Intel OpenVINO dependencies"
for url in "${INTEL_URLS[@]}"; do
curl_with_retry "$url" "$(basename "$url")"
@@ -96,7 +99,6 @@ EOF
rm ./*.deb
$STD apt-mark hold libigdgmm12
dpkg-query -W -f='${Version}\n' intel-opencl-icd >~/.intel_version
rm -f ./Dockerfile
msg_ok "Updated Intel OpenVINO dependencies"
fi
fi
@@ -112,9 +114,11 @@ EOF
msg_ok "Image-processing libraries up to date"
fi
RELEASE="v3.2.4"
if check_for_gh_release "Immich" "immich-app/immich" "${RELEASE}" "each release is tested individually before the version is updated. Please do not open issues for this"; then
if [[ $(cat ~/.immich) > "2.5.1" ]]; then
msg_warn "The update takes 5-15 minutes, do not interrupt it"
PREV_IMMICH="$(cat ~/.immich)"
# An interrupted update leaves app/ empty, so there may be no immich-admin to call.
if [[ "$PREV_IMMICH" > "2.5.1" && -x /opt/immich/app/bin/immich-admin ]]; then
msg_info "Enabling Maintenance Mode"
cd /opt/immich/app/bin
$STD ./immich-admin enable-maintenance-mode || true
@@ -272,13 +276,16 @@ EOF
msg_ok "Pre-installed Python ${ML_PYTHON}"
msg_info "Updating Intel OpenVINO machine-learning"
for attempt in $(seq 1 3); do
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT -Pnu immich uv sync --extra openvino --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
[[ $attempt -lt 3 ]] && msg_warn "uv sync attempt $attempt failed, retrying..." && sleep 10
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT,UV_CONCURRENT_DOWNLOADS,UV_CONCURRENT_BUILDS,UV_CONCURRENT_INSTALLS -Pnu immich uv sync --extra openvino --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
[[ $attempt -eq 3 ]] && { ML_FAILED=1; break; }
# Parallel fetches can trip DNS rate limits (AdGuard, Pi-hole); retry one at a time.
export UV_CONCURRENT_DOWNLOADS=1 UV_CONCURRENT_BUILDS=1 UV_CONCURRENT_INSTALLS=1
msg_warn "uv sync attempt $attempt failed, retrying one download at a time..." && sleep 10
done
patchelf --clear-execstack "${VIRTUAL_ENV}/lib/python3.13/site-packages/onnxruntime/capi/onnxruntime_pybind11_state.cpython-313-$(arch_resolve "x86_64" "aarch64")-linux-gnu.so"
msg_ok "Updated Intel OpenVINO machine-learning"
[[ "${ML_FAILED:-0}" == 1 ]] || patchelf --clear-execstack "${VIRTUAL_ENV}/lib/python3.13/site-packages/onnxruntime/capi/onnxruntime_pybind11_state.cpython-313-$(arch_resolve "x86_64" "aarch64")-linux-gnu.so"
[[ "${ML_FAILED:-0}" == 1 ]] || msg_ok "Updated Intel OpenVINO machine-learning"
else
ML_PYTHON="python3.11"
ML_PYTHON="python3.13"
msg_info "Pre-installing Python ${ML_PYTHON} for machine-learning"
for attempt in $(seq 1 3); do
$STD sudo --preserve-env=VIRTUAL_ENV -Pnu immich uv python install "${ML_PYTHON}" && break
@@ -287,11 +294,15 @@ EOF
msg_ok "Pre-installed Python ${ML_PYTHON}"
msg_info "Updating machine-learning"
for attempt in $(seq 1 3); do
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT -Pnu immich uv sync --extra cpu --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
[[ $attempt -lt 3 ]] && msg_warn "uv sync attempt $attempt failed, retrying..." && sleep 10
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT,UV_CONCURRENT_DOWNLOADS,UV_CONCURRENT_BUILDS,UV_CONCURRENT_INSTALLS -Pnu immich uv sync --extra cpu --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
[[ $attempt -eq 3 ]] && { ML_FAILED=1; break; }
# Parallel fetches can trip DNS rate limits (AdGuard, Pi-hole); retry one at a time.
export UV_CONCURRENT_DOWNLOADS=1 UV_CONCURRENT_BUILDS=1 UV_CONCURRENT_INSTALLS=1
msg_warn "uv sync attempt $attempt failed, retrying one download at a time..." && sleep 10
done
msg_ok "Updated machine-learning"
[[ "${ML_FAILED:-0}" == 1 ]] || msg_ok "Updated machine-learning"
fi
[[ "${ML_FAILED:-0}" == 1 ]] && msg_warn "uv sync failed three times, machine learning was not updated"
cd "$SRC_DIR"
cp -a machine-learning/{ann,immich_ml} "$ML_DIR"
[[ -f "$INSTALL_DIR"/ml_start.sh ]] && mv "$INSTALL_DIR"/ml_start.sh "$ML_DIR"
@@ -318,7 +329,7 @@ EOF
grep -rl /usr/src | xargs -n1 sed -i "s|\/usr/src|$INSTALL_DIR|g"
grep -rlE "'/build'" | xargs -n1 sed -i "s|'/build'|'$APP_DIR'|g"
sed -i "s@\"/cache\"@\"$INSTALL_DIR/cache\"@g" "$ML_DIR"/immich_ml/config.py
[[ ! -f "$GEO_DIR/countryInfo.txt" ]] && curl_with_retry "https://download.geonames.org/export/dump/countryInfo.txt" "countryInfo.txt"
[[ ! -f "$GEO_DIR/countryInfo.txt" ]] && curl_with_retry "https://download.geonames.org/export/dump/countryInfo.txt" "$GEO_DIR/countryInfo.txt"
ln -s "${UPLOAD_DIR:-/opt/immich/upload}" "$APP_DIR"/upload
ln -s "${UPLOAD_DIR:-/opt/immich/upload}" "$ML_DIR"/upload
ln -sfn "$GEO_DIR" "$APP_DIR/geodata"
@@ -332,33 +343,28 @@ EOF
sed -i -e '$a\' "$INSTALL_DIR"/.env
echo "IMMICH_HELMET_FILE=true" >>"$INSTALL_DIR"/.env
fi
if ! grep -q 'MODEL_REVISION' "$INSTALL_DIR"/.env; then
sed -i -e '$a\' "$INSTALL_DIR"/.env
echo "MACHINE_LEARNING_MODEL_REVISION=v2" >>"$INSTALL_DIR"/.env
fi
if grep -q 'ExecStart=/usr/bin/node' /etc/systemd/system/immich-web.service; then
sed -i '/^EnvironmentFile=/d' /etc/systemd/system/immich-web.service
sed -i "s|^ExecStart=.*|ExecStart=${APP_DIR}/bin/start.sh|" /etc/systemd/system/immich-web.service
systemctl daemon-reload
fi
if grep -q "^ExecStart=${INSTALL_DIR}/ml_start.sh" /etc/systemd/system/immich-ml.service; then
sed -i "s|^ExecStart=.*|ExecStart=${ML_DIR}/ml_start.sh|" /etc/systemd/system/immich-ml.service
systemctl daemon-reload
fi
# MickLesk temporary patch for HEIC thumbnail gen
msg_info "Patching media.repository.js"
MEDIA_REPO_JS="/opt/immich/app/dist/repositories/media.repository.js"
if [[ -f "$MEDIA_REPO_JS" ]]; then
python3 - <<'PY'
from pathlib import Path
p = Path('/opt/immich/app/dist/repositories/media.repository.js')
s = p.read_text()
old = "(0, sharp_1.default)(input).metadata()"
new = "(0, sharp_1.default)(input, { unlimited: true, limitInputPixels: false }).metadata()"
if new in s:
print('hotfix already there')
elif old in s:
p.write_text(s.replace(old, new, 1))
print('hotfix applied')
else:
print('pattern not found, skipped')
PY
if grep -qF "(0, sharp_1.default)(input).metadata()" "$MEDIA_REPO_JS" 2>/dev/null; then
msg_info "Patching media.repository.js"
sed -i '0,/(0, sharp_1\.default)(input)\.metadata()/s//(0, sharp_1.default)(input, { unlimited: true, limitInputPixels: false }).metadata()/' "$MEDIA_REPO_JS"
msg_ok "Patched media.repository.js"
fi
msg_ok "Patched media.repository.js"
# chown excluding upload dir contents (may be a mount with restricted permissions)
chown immich:immich "$INSTALL_DIR"
@@ -372,6 +378,15 @@ PY
$STD cd -
msg_ok "Disabled Maintenance Mode"
fi
# A crash loop before the update leaves the units rate-limited, and restart would refuse.
systemctl reset-failed immich-ml immich-web 2>/dev/null || true
if [[ "${ML_FAILED:-0}" == 1 ]]; then
systemctl restart immich-web || true
[[ -f /etc/systemd/system/immich-proxy.service ]] && systemctl restart immich-proxy
echo "$PREV_IMMICH" >~/.immich
msg_error "Immich runs, but without machine learning (see the uv output above). Run update again to retry."
exit 1
fi
systemctl restart immich-ml immich-web
[[ -f /etc/systemd/system/immich-proxy.service ]] && systemctl restart immich-proxy
msg_ok "Updated successfully!"

View File

@@ -38,7 +38,7 @@ function update_script() {
create_backup /opt/jotty/.env /opt/jotty/data /opt/jotty/config
NODE_VERSION="22" NODE_MODULE="yarn" setup_nodejs
NODE_VERSION="24" NODE_MODULE="yarn" setup_nodejs
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "jotty" "fccview/jotty" "prebuild" "latest" "/opt/jotty" "jotty_*_prebuild.tar.gz"
restore_backup

View File

@@ -62,16 +62,7 @@ function update_script() {
msg_info "Updating Kasm"
cd /tmp
msg_warn "WARNING: This script will run an external installer from a third-party source (https://www.kasmweb.com/)."
msg_warn "The following code is NOT maintained or audited by our repository."
msg_warn "If you have any doubts or concerns, please review the installer code before proceeding:"
msg_custom "${TAB3}${GATEWAY}${BGN}${CL}" "\e[1;34m" "→ upgrade.sh inside tar.gz $KASM_URL"
echo
read -r -p "${TAB3}Do you want to continue? [y/N]: " CONFIRM
if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
msg_error "Aborted by user. No changes have been made."
exit 10
fi
confirm_external_installer "https://www.kasmweb.com/" "upgrade.sh inside tar.gz $KASM_URL"
curl_download "/tmp/kasm_release_${KASM_VERSION}.tar.gz" "$KASM_URL"
tar -xf "kasm_release_${KASM_VERSION}.tar.gz"
chmod +x /tmp/kasm_release/install.sh

63
ct/localai.sh Normal file
View File

@@ -0,0 +1,63 @@
#!/usr/bin/env bash
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: Bryan Lieberman (BryanCLieberman)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://localai.io
APP="LocalAI"
var_tags="${var_tags:-ai;llm;api}"
var_cpu="${var_cpu:-4}"
var_ram="${var_ram:-8192}"
var_disk="${var_disk:-30}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-yes}"
var_gpu="${var_gpu:-yes}"
var_unprivileged="${var_unprivileged:-1}"
# Values the install script accepts up front
export var_auth="${var_auth:-no}"
export var_api_key="${var_api_key:-}"
export var_port="${var_port:-8080}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -d /opt/localai ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "localai" "mudler/LocalAI"; then
msg_info "Stopping Service"
systemctl stop localai
msg_ok "Stopped Service"
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "localai" "mudler/LocalAI" "singlefile" "latest" "/opt/localai" "local-ai-v*-linux-$(arch_resolve amd64 arm64)"
msg_info "Starting Service"
systemctl start localai
msg_ok "Started Service"
msg_ok "Updated successfully!"
fi
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}:8080${CL}"
echo -e "${INFO}${YW}Install models from the gallery in the web UI or place GGUF files in /opt/localai_data/models${CL}"

View File

@@ -31,8 +31,18 @@ function update_script() {
exit
fi
RELEASE="v7.4.0"
# Collabora 26.04.4 ignores frame-ancestors in content_security_policy; outside the release
# check so installs already on the current release get it too
if [[ -f /etc/coolwsd/coolwsd.xml ]] && ! grep -q '<frame_ancestors[^>]*>[^<[:space:]]' /etc/coolwsd/coolwsd.xml; then
msg_info "Allowing OpenCloud to embed Collabora"
$STD sudo -u cool coolconfig set net.frame_ancestors "$(sed -n 's/^OC_URL=//p' /etc/opencloud/opencloud.env)"
systemctl restart coolwsd
msg_ok "Allowed OpenCloud to embed Collabora"
fi
RELEASE="v8.1.0"
if check_for_gh_release "OpenCloud" "opencloud-eu/opencloud" "${RELEASE}" "each release is tested individually before the version is updated. Please do not open issues for this"; then
OLD_VERSION="$(cat ~/.opencloud 2>/dev/null)"
msg_info "Stopping services"
systemctl stop opencloud opencloud-wopi
msg_ok "Stopped services"
@@ -70,6 +80,34 @@ function update_script() {
msg_info "Starting services"
systemctl start opencloud opencloud-wopi
msg_ok "Started services"
if [[ -z "$OLD_VERSION" || "${OLD_VERSION#v}" =~ ^[0-7]\. ]]; then
# The index CLI cancels the rebuild when interrupted, so it runs as its own unit and the
# update only waits for it. Restart covers a search service that is still starting.
msg_info "Rebuilding search index (safe to interrupt, it continues in the background)"
REINDEX_START="$(date '+%Y-%m-%d %H:%M:%S')"
systemctl reset-failed opencloud-reindex &>/dev/null || true
$STD systemd-run --unit=opencloud-reindex --uid=opencloud --gid=opencloud \
-p EnvironmentFile=/etc/opencloud/opencloud.env -p Restart=on-failure -p RestartSec=15 \
-p StartLimitIntervalSec=900 -p StartLimitBurst=20 \
/usr/bin/opencloud search index --all-spaces --force-rescan --insecure
while [[ "$(systemctl show -p ActiveState --value opencloud-reindex)" =~ ^(active|activating)$ ]]; do
sleep 10
done
if [[ "$(systemctl show -p ActiveState --value opencloud-reindex)" == "failed" ]]; then
msg_ok "Stopped waiting for the search index rebuild"
msg_warn "The rebuild did not complete, see: journalctl -u opencloud-reindex"
msg_warn "Retry with: systemctl reset-failed opencloud-reindex; systemd-run --unit=opencloud-reindex \
--uid=opencloud --gid=opencloud -p EnvironmentFile=/etc/opencloud/opencloud.env \
/usr/bin/opencloud search index --all-spaces --force-rescan --insecure"
else
msg_ok "Rebuilt search index"
if journalctl -u opencloud-reindex --since "$REINDEX_START" --no-pager | grep -qE '/[0-9]+ ERROR'; then
msg_warn "Some spaces could not be indexed, see: journalctl -u opencloud-reindex"
fi
msg_warn "Once search finds older files, remove the old index: rm -rf /var/lib/opencloud/search/bleve"
fi
fi
msg_ok "Updated successfully"
fi
exit

View File

@@ -7,7 +7,6 @@ source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_
# Source: https://pangolin.net/ | Github: https://github.com/fosrl/pangolin
APP="Pangolin"
PANGOLIN_VERSION="${PANGOLIN_VERSION:-1.23.0}"
var_tags="${var_tags:-proxy}"
var_cpu="${var_cpu:-2}"
var_ram="${var_ram:-4096}"
@@ -38,7 +37,7 @@ function update_script() {
ensure_dependencies build-essential python3
if ! command -v psql &>/dev/null; then
msg_error "This installation uses SQLite and cannot be upgraded to Pangolin ${PANGOLIN_VERSION}."
msg_error "This installation uses SQLite and cannot be upgraded to latest Pangolin."
echo -e "${INFO}${YW}Starting with Pangolin 1.20.0, PostgreSQL is required as the database backend.${CL}"
echo -e "${INFO}${YW}An automatic migration of your existing SQLite data is not supported.${CL}"
echo -e "${INFO}${YW}Please create a new LXC with the Pangolin install script, which sets up PostgreSQL automatically.${CL}"
@@ -48,7 +47,7 @@ function update_script() {
NODE_VERSION="24" setup_nodejs
if check_for_gh_release "pangolin" "fosrl/pangolin" "$PANGOLIN_VERSION" "Pinned to a tested release because Pangolin's schema changes have repeatedly broken unattended updates. To try a newer version at your own risk, run: 'export PANGOLIN_VERSION=<tag>' and re-run update. If it breaks, please open an issue at https://github.com/community-scripts/ProxmoxVE/issues with the error log."; then
if check_for_gh_release "pangolin" "fosrl/pangolin"; then
msg_info "Stopping Service"
systemctl stop pangolin
systemctl stop gerbil
@@ -57,7 +56,7 @@ function update_script() {
DB_URL=$(sed -n 's/.*connection_string: "\(.*\)".*/\1/p' /opt/pangolin/config/config.yml)
create_backup /opt/pangolin/config
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "pangolin" "fosrl/pangolin" "tarball" "$PANGOLIN_VERSION"
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "pangolin" "fosrl/pangolin" "tarball"
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "gerbil" "fosrl/gerbil" "singlefile" "latest" "/usr/bin" "gerbil_linux_$(arch_resolve)"
msg_info "Updating Pangolin"

View File

@@ -15,6 +15,8 @@ var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-yes}"
var_unprivileged="${var_unprivileged:-1}"
export var_paperclip_user="${var_paperclip_user:-}"
export var_paperclip_pass="${var_paperclip_pass:-}"
header_info "$APP"
variables
@@ -59,9 +61,44 @@ function update_script() {
@openai/codex@latest
msg_ok "Updated Agent CLIs"
# Claude Code refuses --dangerously-skip-permissions as root; migrate existing installs to a dedicated user
PAPERCLIP_USER=$(sed -n 's/^User=//p' /etc/systemd/system/paperclip.service)
PAPERCLIP_HOME=$(sed -n 's/^PAPERCLIP_HOME=//p' /opt/paperclip-ai/.env)
PAPERCLIP_HOME="${PAPERCLIP_HOME:-/opt/paperclip-data}"
if [[ -z "$PAPERCLIP_USER" || "$PAPERCLIP_USER" == "root" ]] && [[ "$PAPERCLIP_HOME" != "/opt/paperclip-data" ]]; then
# A custom data dir (e.g. an NFS bind mount) may only be reachable by root; don't move the service off root
msg_warn "PAPERCLIP_HOME is ${PAPERCLIP_HOME}; keeping the service user as root"
PAPERCLIP_USER=root
elif [[ -z "$PAPERCLIP_USER" || "$PAPERCLIP_USER" == "root" ]]; then
PAPERCLIP_USER="${var_paperclip_user:-paperclip}"
if [[ "$PAPERCLIP_USER" == "root" || ! "$PAPERCLIP_USER" =~ ^[a-z_][a-z0-9_-]{0,31}$ ]]; then
msg_error "Invalid var_paperclip_user '${PAPERCLIP_USER}' (must be a non-root lowercase Linux username)"
exit 1
fi
PAPERCLIP_USER_HOME="/home/${PAPERCLIP_USER}"
id -u "$PAPERCLIP_USER" &>/dev/null || useradd -m -d "$PAPERCLIP_USER_HOME" -s /bin/bash "$PAPERCLIP_USER"
passwd -S "$PAPERCLIP_USER" 2>/dev/null | grep -q " P " || passwd -l "$PAPERCLIP_USER" &>/dev/null
mkdir -p "${PAPERCLIP_USER_HOME}/.claude" "${PAPERCLIP_USER_HOME}/.codex"
[[ -d /root/.claude ]] && cp -a /root/.claude/. "${PAPERCLIP_USER_HOME}/.claude/"
[[ -d /root/.codex ]] && cp -a /root/.codex/. "${PAPERCLIP_USER_HOME}/.codex/"
sed -i \
-e "s|^User=.*|User=${PAPERCLIP_USER}\nGroup=${PAPERCLIP_USER}|" \
-e "s|^Environment=HOME=.*|Environment=HOME=${PAPERCLIP_USER_HOME}|" \
-e "s|^Environment=CODEX_HOME=.*|Environment=CODEX_HOME=${PAPERCLIP_USER_HOME}/.codex|" \
-e "s|/root/.local/bin|${PAPERCLIP_USER_HOME}/.local/bin|" \
/etc/systemd/system/paperclip.service
systemctl daemon-reload
fi
PAPERCLIP_USER_HOME=$(getent passwd "$PAPERCLIP_USER" | cut -d: -f6)
chmod 600 /opt/paperclip-ai/.env
chown -R "${PAPERCLIP_USER}:${PAPERCLIP_USER}" /opt/paperclip-ai "$PAPERCLIP_USER_HOME"
if [[ "$PAPERCLIP_HOME" == "/opt/paperclip-data" && -d /opt/paperclip-data ]]; then
chown -R "${PAPERCLIP_USER}:${PAPERCLIP_USER}" /opt/paperclip-data
fi
msg_info "Running Database Migrations"
set -a && source /opt/paperclip-ai/.env && set +a
$STD pnpm db:migrate
$STD runuser -u "$PAPERCLIP_USER" -- env HOME="$PAPERCLIP_USER_HOME" bash -c 'cd /opt/paperclip-ai && pnpm db:migrate'
msg_ok "Ran Database Migrations"
msg_info "Starting Service"

106
ct/pricebuddy.sh Normal file
View File

@@ -0,0 +1,106 @@
#!/usr/bin/env bash
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/jez500/pricebuddy
APP="PriceBuddy"
var_tags="${var_tags:-shopping;price-tracker}"
var_cpu="${var_cpu:-2}"
var_ram="${var_ram:-3072}"
var_disk="${var_disk:-10}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-no}" # the bundled scraper runs Google Chrome, which is amd64-only
var_unprivileged="${var_unprivileged:-1}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -d /opt/pricebuddy ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "pricebuddy" "jez500/pricebuddy"; then
msg_info "Stopping PriceBuddy Worker"
systemctl stop pricebuddy-worker
msg_ok "Stopped PriceBuddy Worker"
setup_composer
NODE_VERSION="22" setup_nodejs
create_backup /opt/pricebuddy/.env /opt/pricebuddy/storage
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "pricebuddy" "jez500/pricebuddy" "tarball"
restore_backup
msg_info "Updating PriceBuddy"
cd /opt/pricebuddy
sed -i "s/^APP_VERSION=.*/APP_VERSION=$(cat ~/.pricebuddy)/" .env
$STD composer install --no-dev --optimize-autoloader --no-interaction
$STD npm install
$STD npm run build
$STD php artisan storage:link
$STD php artisan migrate --force
$STD php artisan optimize
$STD php artisan icons:cache
$STD php artisan buddy:regenerate-price-cache
chown -R www-data:www-data /opt/pricebuddy
msg_ok "Updated PriceBuddy"
msg_info "Starting PriceBuddy Worker"
systemctl start pricebuddy-worker
msg_ok "Started PriceBuddy Worker"
msg_ok "Updated successfully!"
fi
if check_for_gh_release "seleniumbase-scrapper" "jez500/seleniumbase-scrapper"; then
msg_info "Stopping SeleniumBase Scrapper"
systemctl stop seleniumbase-scrapper
msg_ok "Stopped SeleniumBase Scrapper"
msg_info "Updating Google Chrome"
apt_update_safe
upgrade_packages_with_retry google-chrome-stable
msg_ok "Updated Google Chrome"
PYTHON_VERSION="3.12" setup_uv
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "seleniumbase-scrapper" "jez500/seleniumbase-scrapper" "tarball"
msg_info "Updating SeleniumBase Scrapper"
$STD uv venv --python 3.12 /opt/seleniumbase-scrapper/.venv
$STD uv pip install --python /opt/seleniumbase-scrapper/.venv/bin/python \
"seleniumbase==$(sed -n 's/^ARG SELENIUMBASE_VERSION=v//p' /opt/seleniumbase-scrapper/Dockerfile)" \
flask \
beautifulsoup4
$STD /opt/seleniumbase-scrapper/.venv/bin/seleniumbase get chromedriver
msg_ok "Updated SeleniumBase Scrapper"
msg_info "Starting SeleniumBase Scrapper"
systemctl start seleniumbase-scrapper
msg_ok "Started SeleniumBase Scrapper"
fi
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}${CL}"
echo -e "${INFO}${YW}Log in as admin@example.com - the password is APP_USER_PASSWORD in /opt/pricebuddy/.env${CL}"

View File

@@ -41,7 +41,7 @@ function update_script() {
if grep -q 'start.sh' /etc/systemd/system/radicale.service; then
sed -i -e '/^Description/i[Unit]' \
-e '\|^ExecStart|iWorkingDirectory=/opt/radicale' \
-e 's|^ExecStart=.*|ExecStart=/usr/local/bin/uv run -m radicale --config /etc/radicale/config|' /etc/systemd/system/radicale.service
-e 's|^ExecStart=.*|ExecStart=/usr/local/bin/uv run --extra bcrypt --extra argon2 -m radicale --config /etc/radicale/config|' /etc/systemd/system/radicale.service
systemctl daemon-reload
fi
if [[ ! -f /etc/radicale/config ]]; then
@@ -70,6 +70,14 @@ EOF
msg_ok "Started service"
msg_ok "Updated Successfully!"
fi
if grep -q 'uv run -m radicale' /etc/systemd/system/radicale.service && grep -q '^argon2 *=' /opt/radicale/pyproject.toml; then
msg_info "Enabling bcrypt/argon2 support"
sed -i 's|uv run -m radicale|uv run --extra bcrypt --extra argon2 -m radicale|' /etc/systemd/system/radicale.service
systemctl daemon-reload
systemctl restart radicale
msg_ok "Enabled bcrypt/argon2 support"
fi
exit
}

View File

@@ -30,6 +30,7 @@ function update_script() {
exit
fi
JAVA_VERSION="25" setup_java
if check_for_gh_release "thingsboard" "thingsboard/thingsboard"; then
msg_info "Stopping Service"
systemctl stop thingsboard

58
ct/tvheadend.sh Normal file
View File

@@ -0,0 +1,58 @@
#!/usr/bin/env bash
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: Nicolas Pastorello (opastorello)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://tvheadend.org/ | Github: https://github.com/tvheadend/tvheadend
APP="Tvheadend"
var_tags="${var_tags:-media;pvr;tv;dvr}"
var_cpu="${var_cpu:-2}"
var_ram="${var_ram:-2048}"
var_disk="${var_disk:-8}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
#var_arm64="${var_arm64:-no}" # unset = ask the user; set yes/no only when verified
var_unprivileged="${var_unprivileged:-1}"
export var_admin_user="${var_admin_user:-admin}"
export var_admin_pass="${var_admin_pass:-$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | cut -c1-13)}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -d /var/lib/tvheadend ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
msg_info "Updating Tvheadend"
$STD apt update
$STD apt install -y tvheadend
msg_ok "Updated Tvheadend"
msg_info "Restarting Service"
systemctl restart tvheadend
msg_ok "Restarted Service"
msg_ok "Updated successfully!"
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}:9981${CL}"
echo -e "${INFO}${YW}Admin Username: ${var_admin_user}${CL}"
echo -e "${INFO}${YW}Admin Password: ${var_admin_pass}${CL}"

View File

@@ -3,7 +3,7 @@ _cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../cor
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: Joost van den Berg (montagneId)
# License: MIT | https://github.com/montagneid/ProxmoxVED/raw/main/LICENSE
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/umbraco/Umbraco-CMS
APP="Umbraco"

View File

@@ -148,6 +148,23 @@ EOF
msg_ok "Migrated wanderer services"
fi
if ! grep -q '^POCKETBASE_PROXY_SECRET=' /opt/wanderer/.env; then
msg_info "Adding POCKETBASE_PROXY_SECRET"
echo "POCKETBASE_PROXY_SECRET=$(openssl rand -hex 32)" >>/opt/wanderer/.env
systemctl restart wanderer-web
msg_ok "Added POCKETBASE_PROXY_SECRET"
fi
if [[ -f /opt/wanderer_data/plugins/plugin.json ]]; then
msg_info "Reinstalling wanderer plugins, one directory each"
find /opt/wanderer_data/plugins -maxdepth 1 -type f -delete
for plugin in hammerhead komoot strava; do
rm -f ~/.wanderer-plugin-${plugin}
fetch_and_deploy_gh_release "wanderer-plugin-${plugin}" "open-wanderer/wanderer" "prebuild" "latest" "/opt/wanderer_data/plugins/${plugin}" "wanderer-plugin-${plugin}.tar.gz" || msg_warn "Failed to install wanderer plugin: ${plugin}"
done
msg_ok "Reinstalled wanderer plugins"
fi
if check_for_gh_release "wanderer" "open-wanderer/wanderer"; then
msg_info "Stopping service"
systemctl stop wanderer-web
@@ -170,7 +187,7 @@ EOF
[[ -e /opt/wanderer/db/data/plugins ]] || ln -sfn /opt/wanderer_data/plugins /opt/wanderer/db/data/plugins
msg_info "Installing wanderer plugins"
for plugin in hammerhead komoot strava; do
fetch_and_deploy_gh_release "wanderer-plugin-${plugin}" "open-wanderer/wanderer" "prebuild" "${CHECK_UPDATE_RELEASE:-latest}" "/opt/wanderer_data/plugins" "wanderer-plugin-${plugin}.tar.gz" || msg_warn "Failed to install wanderer plugin: ${plugin}"
fetch_and_deploy_gh_release "wanderer-plugin-${plugin}" "open-wanderer/wanderer" "prebuild" "${CHECK_UPDATE_RELEASE:-latest}" "/opt/wanderer_data/plugins/${plugin}" "wanderer-plugin-${plugin}.tar.gz" || msg_warn "Failed to install wanderer plugin: ${plugin}"
done
msg_ok "Installed wanderer plugins"
msg_ok "Updated wanderer"

67
ct/weblate.sh Normal file
View File

@@ -0,0 +1,67 @@
#!/usr/bin/env bash
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/WeblateOrg/weblate
APP="Weblate"
var_tags="${var_tags:-translation;localization}"
var_cpu="${var_cpu:-2}"
var_ram="${var_ram:-3072}"
var_disk="${var_disk:-10}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-yes}"
var_unprivileged="${var_unprivileged:-1}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -d /opt/weblate ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "weblate" "WeblateOrg/weblate"; then
msg_info "Stopping Weblate"
systemctl stop weblate weblate-celery
msg_ok "Stopped Weblate"
PYTHON_VERSION="3.14" setup_uv
USE_ORIGINAL_FILENAME=true fetch_and_deploy_gh_release "weblate" "WeblateOrg/weblate" "singlefile" "latest" "/opt/weblate" "weblate-*-py3-none-any.whl"
msg_info "Updating Weblate"
$STD uv pip install --python /opt/weblate/.venv/bin/python --compile-bytecode /opt/weblate/weblate-*.whl "weblate[all,wsgi]"
rm -f /opt/weblate/weblate-*.whl
set -a
source /opt/weblate_data/weblate.env
set +a
$STD /opt/weblate/.venv/bin/weblate migrate --noinput
$STD /opt/weblate/.venv/bin/weblate collectstatic --noinput
msg_ok "Updated Weblate"
msg_info "Starting Weblate"
systemctl start weblate-celery weblate
msg_ok "Started Weblate"
msg_ok "Updated successfully!"
fi
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}${CL}"

View File

@@ -31,6 +31,20 @@ function update_script() {
exit
fi
if ! grep -q "@private" /etc/caddy/Caddyfile; then
msg_info "Blocking direct access to webtrees data"
cp /etc/caddy/Caddyfile /etc/caddy/Caddyfile.bak
sed -i '\|root \* /opt/webtrees|a\ @private path /app/* /data/* /modules_v4/* /resources/* /vendor/* /.*\n respond @private 403' /etc/caddy/Caddyfile
if grep -q "@private" /etc/caddy/Caddyfile && caddy validate --config /etc/caddy/Caddyfile &>/dev/null; then
rm -f /etc/caddy/Caddyfile.bak
systemctl reload-or-restart caddy
msg_ok "Blocked direct access to webtrees data"
else
mv /etc/caddy/Caddyfile.bak /etc/caddy/Caddyfile
msg_warn "Could not patch /etc/caddy/Caddyfile - deny /data/ there by hand"
fi
fi
if check_for_gh_release "webtrees" "fisharebest/webtrees"; then
msg_info "Stopping Service"
PHP_VER=$(php -r 'echo PHP_MAJOR_VERSION . "." . PHP_MINOR_VERSION;')

View File

@@ -30,7 +30,7 @@ function update_script() {
exit
fi
NODE_VERSION="24" NODE_MODULE="yarn,node-gyp" setup_nodejs
NODE_VERSION="26" NODE_MODULE="yarn,node-gyp" setup_nodejs
if check_for_gh_release "wikijs" "requarks/wiki"; then
msg_info "Verifying whether ${APP}' new release is v3.x+ and current install uses SQLite."

View File

@@ -49,8 +49,12 @@ update_deb_based() {
ensure_dependencies zstd
mkdir -p /opt/backups
BACKUP_VERSION="$(<"$HOME/.zigbee2mqtt")"
BACKUP_FILE="/opt/backups/${APP}_backup_${BACKUP_VERSION}.tar.zst"
$STD tar -cf - -C /opt zigbee2mqtt | zstd -q -o "$BACKUP_FILE"
BACKUP_FILE="$(mktemp "/opt/backups/${APP}_backup_${BACKUP_VERSION}_XXXXXX.tar.zst")"
tar -cf - -C /opt zigbee2mqtt | $STD zstd -q -f -o "$BACKUP_FILE" || {
local backup_exit_code=$?
rm -f "$BACKUP_FILE"
return "$backup_exit_code"
}
ls -t /opt/backups/${APP}_backup_*.tar.zst 2>/dev/null | tail -n +6 | xargs -r rm -f
msg_ok "Backup Created (${BACKUP_VERSION})"

View File

@@ -0,0 +1,107 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/Mintplex-Labs/anything-llm
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
msg_info "Installing Dependencies"
$STD apt install -y \
build-essential \
python3-dev \
libgomp1 \
git \
chromium
msg_ok "Installed Dependencies"
NODE_VERSION="22" NODE_MODULE="yarn" setup_nodejs
fetch_and_deploy_gh_release "anythingllm" "Mintplex-Labs/anything-llm" "tarball"
msg_info "Configuring AnythingLLM"
mkdir -p /opt/anythingllm_data/storage
cp -RTn /opt/anythingllm/server/storage /opt/anythingllm_data/storage 2>/dev/null || true
rm -rf /opt/anythingllm/server/storage
ln -sfn /opt/anythingllm_data/storage /opt/anythingllm/server/storage
cat <<EOF >/opt/anythingllm/server/.env
SERVER_PORT=3001
STORAGE_DIR="/opt/anythingllm/server/storage"
JWT_SECRET="$(openssl rand -hex 32)"
SIG_KEY="$(openssl rand -hex 32)"
SIG_SALT="$(openssl rand -hex 32)"
VECTOR_DB="lancedb"
EOF
cat <<EOF >/opt/anythingllm/collector/.env
STORAGE_DIR="/opt/anythingllm/server/storage"
EOF
cat <<EOF >/opt/anythingllm/frontend/.env
VITE_API_BASE='/api'
EOF
msg_ok "Configured AnythingLLM"
msg_info "Building AnythingLLM (Patience)"
cd /opt/anythingllm
export PUPPETEER_SKIP_DOWNLOAD=true
export NODE_OPTIONS="--max-old-space-size=3072"
$STD yarn setup
cd /opt/anythingllm/frontend
$STD yarn build
cp -R /opt/anythingllm/frontend/dist /opt/anythingllm/server/public
cd /opt/anythingllm/server
$STD npx prisma generate --schema=./prisma/schema.prisma
$STD npx prisma migrate deploy --schema=./prisma/schema.prisma
msg_ok "Built AnythingLLM"
msg_info "Creating Services"
cat <<EOF >/etc/systemd/system/anythingllm.service
[Unit]
Description=AnythingLLM Server
Wants=network-online.target
After=network-online.target
[Service]
Type=simple
User=root
WorkingDirectory=/opt/anythingllm/server
Environment=NODE_ENV=production
ExecStart=/usr/bin/node index.js
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
cat <<EOF >/etc/systemd/system/anythingllm-collector.service
[Unit]
Description=AnythingLLM Collector
Wants=network-online.target
After=network-online.target anythingllm.service
[Service]
Type=simple
User=root
WorkingDirectory=/opt/anythingllm/collector
Environment=NODE_ENV=production
Environment=PUPPETEER_EXECUTABLE_PATH=/usr/bin/chromium
ExecStart=/usr/bin/node index.js
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
systemctl enable -q --now anythingllm anythingllm-collector
msg_ok "Created Services"
motd_ssh
customize
cleanup_lxc

View File

@@ -17,7 +17,8 @@ msg_info "Installing Aria2"
$STD apt install -y aria2
msg_ok "Installed Aria2"
read -r -p "${TAB3}Would you like to add AriaNG? <y/N> " prompt
prompt="${var_aria2_ariang:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add AriaNG? <y/N> " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
msg_info "Installing Dependencies"
$STD apt install -y nginx

View File

@@ -33,7 +33,12 @@ PNPM_VERSION=$(jq -r '.packageManager | ltrimstr("pnpm@")' /opt/bookorbit/packag
$STD corepack prepare "pnpm@${PNPM_VERSION}" --activate
$STD pnpm install --frozen-lockfile
$STD pnpm --filter client run build-only
# vite's bundler (rolldown) crashes at random on some builds, rolldown#10860.
for attempt in 1 2 3; do
$STD pnpm --filter client run build-only && break
[[ $attempt -eq 3 ]] && { msg_error "Client build failed three times"; exit 1; }
msg_warn "Client build failed (attempt $attempt), retrying"
done
$STD pnpm --filter server run build
cp -r /opt/bookorbit/client/dist /opt/bookorbit/server/public
mkdir -p /opt/bookorbit/server/migrations

View File

@@ -20,16 +20,7 @@ $STD apt install -y \
msg_ok "Installed Dependencies"
RELEASE=$(get_latest_github_release "bunkerity/bunkerweb")
msg_warn "WARNING: This script will run an external installer from a third-party source (install-bunkerweb.sh)."
msg_warn "The following code is NOT maintained or audited by our repository."
msg_warn "If you have any doubts or concerns, please review the installer code before proceeding:"
msg_custom "${TAB3}${GATEWAY}${BGN}${CL}" "\e[1;34m" "→ https://github.com/bunkerity/bunkerweb/raw/v${RELEASE}/misc/install-bunkerweb.sh"
echo
read -r -p "${TAB3}Do you want to continue? [y/N]: " CONFIRM
if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
msg_error "Aborted by user. No changes have been made."
exit 10
fi
confirm_external_installer "install-bunkerweb.sh" "https://github.com/bunkerity/bunkerweb/raw/v${RELEASE}/misc/install-bunkerweb.sh"
msg_info "Installing BunkerWeb (Patience)"
curl -fsSL -o install-bunkerweb.sh "https://github.com/bunkerity/bunkerweb/raw/v${RELEASE}/misc/install-bunkerweb.sh"
chmod +x install-bunkerweb.sh

View File

@@ -24,7 +24,8 @@ cd /opt/bytestash/client
$STD npm install
msg_ok "Installed ByteStash"
read -rp "${TAB3}Do you want to allow registration of multiple accounts? [y/n]: " allowreg
allowreg="${var_bytestash_registration:-}"
[[ -n "$allowreg" ]] || read -rp "${TAB3}Do you want to allow registration of multiple accounts? [y/n]: " allowreg
msg_info "Creating Service"
cat <<EOF >/etc/systemd/system/bytestash-backend.service
@@ -42,7 +43,7 @@ Environment=JWT_SECRET=$JWT_SECRET
WantedBy=multi-user.target
EOF
if [[ "$allowreg" =~ ^[Yy]$ ]]; then
if [[ "${allowreg,,}" =~ ^(y|yes)$ ]]; then
sed -i '8i\Environment=ALLOW_NEW_ACCOUNTS=true' /etc/systemd/system/bytestash-backend.service
fi

View File

@@ -14,23 +14,11 @@ network_check
update_os
setup_deb_based() {
msg_info "Installing Dependencies"
$STD apt install -y \
debian-keyring \
debian-archive-keyring \
apt-transport-https
msg_ok "Installed Dependencies"
fetch_and_deploy_gh_release "caddy" "caddyserver/caddy" "binary" "latest" "/opt/caddy" "caddy_*_linux_$(arch_resolve).deb"
systemctl enable -q --now caddy
msg_info "Installing Caddy"
setup_deb822_repo \
"caddy" \
"https://dl.cloudsmith.io/public/caddy/stable/gpg.key" \
"https://dl.cloudsmith.io/public/caddy/stable/deb/debian" \
"any-version"
$STD apt install -y caddy
msg_ok "Installed Caddy"
read -r -p "${TAB3}Would you like to install xCaddy Addon? <y/N> " prompt
prompt="${var_caddy_xcaddy:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to install xCaddy Addon? <y/N> " prompt
if [[ "${prompt,,}" =~ ^(y|yes)$ ]]; then
setup_go
fetch_and_deploy_gh_release "xcaddy" "caddyserver/xcaddy" "binary"
@@ -75,7 +63,8 @@ EOF
EOF
msg_ok "Installed Caddy"
read -r -p "${TAB3}Would you like to install xCaddy Addon? <y/N> " prompt
prompt="${var_caddy_xcaddy:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to install xCaddy Addon? <y/N> " prompt
if [[ "${prompt,,}" =~ ^(y|yes)$ ]]; then
GO_VERSION="$(curl -fsSL https://go.dev/VERSION?m=text | head -1 | cut -c3-)" setup_go
fetch_and_deploy_gh_release "xcaddy" "caddyserver/xcaddy" "prebuild" "latest" "/opt/xcaddy" "xcaddy_*_linux_$(arch_resolve).tar.gz"

View File

@@ -13,16 +13,7 @@ setting_up_container
network_check
update_os
msg_warn "WARNING: This script will run an external installer from a third-party source (https://casaos.zimaspace.com/)."
msg_warn "The following code is NOT maintained or audited by our repository."
msg_warn "If you have any doubts or concerns, please review the installer code before proceeding:"
msg_custom "${TAB3}${GATEWAY}${BGN}${CL}" "\e[1;34m" "→ https://get.casaos.io/"
echo
read -r -p "${TAB3}Do you want to continue? [y/N]: " CONFIRM
if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
msg_error "Aborted by user. No changes have been made."
exit 10
fi
confirm_external_installer "https://casaos.zimaspace.com/" "https://get.casaos.io/"
msg_info "Installing CasaOS (Patience)"
DOCKER_CONFIG_PATH='/etc/docker/daemon.json'
mkdir -p $(dirname $DOCKER_CONFIG_PATH)

View File

@@ -0,0 +1,69 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: fabriziosalmi
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/fabriziosalmi/certmate
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
PYTHON_VERSION="3.12" setup_uv
fetch_and_deploy_gh_release "certmate" "fabriziosalmi/certmate" "tarball"
msg_info "Installing CertMate Dependencies"
cd /opt/certmate
$STD uv venv --python 3.12 /opt/certmate/.venv
# requirements.lock is the fully pinned set the official image is built from
$STD uv pip sync --python /opt/certmate/.venv/bin/python requirements.lock
$STD /opt/certmate/.venv/bin/certbot --version
msg_ok "Installed CertMate Dependencies"
msg_info "Configuring CertMate"
mkdir -p /opt/certmate_data/{certificates,data,backups,logs}
cat <<EOF >/opt/certmate_data/.env
API_BEARER_TOKEN=$(openssl rand -hex 32)
SECRET_KEY=$(openssl rand -hex 32)
CERTMATE_BACKUP_PASSPHRASE=$(openssl rand -hex 32)
BEHIND_PROXY=false
EOF
chmod 600 /opt/certmate_data/.env
msg_ok "Configured CertMate"
msg_info "Creating Service"
cat <<EOF >/etc/systemd/system/certmate.service
[Unit]
Description=CertMate SSL Certificate Manager
After=network-online.target
Wants=network-online.target
[Service]
Type=simple
User=root
WorkingDirectory=/opt/certmate
Environment=PATH=/opt/certmate/.venv/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
Environment=CERTMATE_CERT_DIR=/opt/certmate_data/certificates
Environment=CERTMATE_DATA_DIR=/opt/certmate_data/data
Environment=CERTMATE_BACKUP_DIR=/opt/certmate_data/backups
Environment=CERTMATE_LOGS_DIR=/opt/certmate_data/logs
Environment=ACME_CHALLENGES_DIR=/opt/certmate_data/data/acme-challenges
EnvironmentFile=/opt/certmate_data/.env
# One worker: the renewal scheduler, sessions and rate limits live in-process
ExecStart=/opt/certmate/.venv/bin/gunicorn --bind 0.0.0.0:8000 --workers 1 --threads 8 --timeout 300 --no-control-socket app:app
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
systemctl enable -q --now certmate
msg_ok "Created Service"
motd_ssh
customize
cleanup_lxc

View File

@@ -19,16 +19,7 @@ $STD apt install -y \
xvfb
msg_ok "Installed Dependencies"
msg_warn "WARNING: This script will run an external installer from a third-party source (https://getchannels.com)."
msg_warn "The following code is NOT maintained or audited by our repository."
msg_warn "If you have any doubts or concerns, please review the installer code before proceeding:"
msg_custom "${TAB3}${GATEWAY}${BGN}${CL}" "\e[1;34m" "→ https://getchannels.com/dvr/setup.sh"
echo
read -r -p "${TAB3}Do you want to continue? [y/N]: " CONFIRM
if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
msg_error "Aborted by user. No changes have been made."
exit 10
fi
confirm_external_installer "https://getchannels.com" "https://getchannels.com/dvr/setup.sh"
setup_hwaccel

View File

@@ -0,0 +1,84 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/MoldyTaint/Cinephage
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
msg_info "Installing Dependencies"
$STD apt install -y \
build-essential \
python3 \
libasound2t64 \
libgtk-3-0t64 \
libx11-xcb1 \
xvfb
msg_ok "Installed Dependencies"
setup_ffmpeg
NODE_VERSION="24" setup_nodejs
fetch_and_deploy_gh_release "cinephage" "MoldyTaint/Cinephage" "tarball"
msg_info "Building Cinephage"
cd /opt/cinephage
$STD npm ci
$STD npm run build
$STD npm prune --omit=dev
msg_ok "Built Cinephage"
msg_info "Installing Camoufox"
$STD /opt/cinephage/node_modules/.bin/camoufox-js fetch
msg_ok "Installed Camoufox"
msg_info "Configuring Cinephage"
mkdir -p /opt/cinephage_data/indexers/custom /opt/cinephage_data/external-lists/custom
cat <<EOF >/opt/cinephage_data/.env
NODE_ENV=production
HOST=0.0.0.0
PORT=3000
APP_VERSION=$(cat ~/.cinephage)
BETTER_AUTH_SECRET=$(openssl rand -base64 32)
DATA_DIR=/opt/cinephage_data
INDEXER_DEFINITIONS_PATH=/opt/cinephage/data/indexers/definitions
INDEXER_CUSTOM_DEFINITIONS_PATH=/opt/cinephage_data/indexers/custom
EXTERNAL_LISTS_PRESETS_PATH=/opt/cinephage/data/external-lists/presets
EXTERNAL_LISTS_CUSTOM_PRESETS_PATH=/opt/cinephage_data/external-lists/custom
CAPTCHA_ADDON_PATH=/opt/cinephage/src/lib/server/captcha/browser/addon
FFPROBE_PATH=/usr/bin/ffprobe
EOF
chmod 600 /opt/cinephage_data/.env
msg_ok "Configured Cinephage"
msg_info "Creating Service"
cat <<EOF >/etc/systemd/system/cinephage.service
[Unit]
Description=Cinephage
After=network.target
[Service]
Type=simple
User=root
WorkingDirectory=/opt/cinephage
EnvironmentFile=/opt/cinephage_data/.env
Environment=NODE_OPTIONS=--max-old-space-size=2048
ExecStart=/usr/bin/node server.js
Restart=on-failure
RestartSec=10
[Install]
WantedBy=multi-user.target
EOF
systemctl enable -q --now cinephage
msg_ok "Created Service"
motd_ssh
customize
cleanup_lxc

View File

@@ -31,7 +31,10 @@ sed -i "s/root//g" /etc/cockpit/disallowed-users
msg_ok "Installed Cockpit"
# 45Drives only publishes amd64 packages
[[ "$(arch_resolve)" == "arm64" ]] || read -r -p "Would you like to install 45Drives' cockpit-file-sharing, cockpit-identities, and cockpit-navigator <y/N> " prompt
if [[ "$(arch_resolve)" != "arm64" ]]; then
prompt="${var_cockpit_45drives:-}"
[[ -n "$prompt" ]] || read -r -p "Would you like to install 45Drives' cockpit-file-sharing, cockpit-identities, and cockpit-navigator <y/N> " prompt
fi
if [[ "${prompt,,}" =~ ^(y|yes)$ ]]; then
msg_info "Installing 45Drives' cockpit extensions"
setup_deb822_repo "45drives" \

View File

@@ -19,14 +19,15 @@ msg_ok "Installed Dependencies"
NODE_VERSION="22" setup_nodejs
read -rp "${TAB3}Install OnlyOffice components instead of CKEditor? (Y/N): " onlyoffice
onlyoffice="${var_cryptpad_onlyoffice:-}"
[[ -n "$onlyoffice" ]] || read -rp "${TAB3}Install OnlyOffice components instead of CKEditor? (Y/N): " onlyoffice
fetch_and_deploy_gh_release "cryptpad" "cryptpad/cryptpad" "tarball"
msg_info "Setup CryptPad"
cd /opt/cryptpad
$STD npm ci --allow-git=all
$STD npm run install:components
if [[ "$onlyoffice" =~ ^[Yy]$ ]]; then
if [[ "${onlyoffice,,}" =~ ^(y|yes)$ ]]; then
$STD bash -c "./install-onlyoffice.sh --accept-license"
fi
cp config/config.example.js config/config.js

View File

@@ -203,7 +203,6 @@ server {
proxy_set_header X-Real-IP \$remote_addr;
proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto \$scheme;
proxy_set_header X-Accel-Mapping /opt/discourse/public/=/downloads/;
}
}
EOF

View File

@@ -15,12 +15,16 @@ update_os
setup_deb_based() {
setup_docker
read -r -p "${TAB3}Expose Docker TCP socket (insecure) ? [n = No, l = Local only (127.0.0.1), a = All interfaces (0.0.0.0)] <n/l/a>: " socket_choice
if [[ -n "${var_docker_socket:-}" ]]; then
socket_choice="$var_docker_socket"
else
read -r -p "${TAB3}Expose Docker TCP socket (insecure) ? [n = No, l = Local only (127.0.0.1), a = All interfaces (0.0.0.0)] <n/l/a>: " socket_choice
fi
case "${socket_choice,,}" in
l)
l | local)
socket="tcp://127.0.0.1:2375"
;;
a)
a | all)
socket="tcp://0.0.0.0:2375"
;;
*)
@@ -66,8 +70,12 @@ setup_alpine() {
msg_ok "Installed Docker"
DOCKER_COMPOSE_LATEST_VERSION=$(get_latest_github_release "docker/compose" false)
read -r -p "${TAB3}Would you like to add Docker Compose? <y/N> " prompt
if [[ "${prompt,,}" =~ ^(y|yes)$ ]]; then
if [[ -n "${var_docker_compose:-}" ]]; then
prompt="$var_docker_compose"
else
read -r -p "${TAB3}Would you like to add Docker Compose? <y/N> " prompt
fi
if [[ "${prompt,,}" =~ ^(y|yes|true)$ ]]; then
msg_info "Installing Docker Compose $DOCKER_COMPOSE_LATEST_VERSION"
DOCKER_CONFIG=${DOCKER_CONFIG:-$HOME/.docker}
mkdir -p "$DOCKER_CONFIG"/cli-plugins
@@ -75,13 +83,23 @@ setup_alpine() {
chmod +x "$DOCKER_CONFIG"/cli-plugins/docker-compose
msg_ok "Installed Docker Compose $DOCKER_COMPOSE_LATEST_VERSION"
fi
read -r -p "${TAB3}Would you like to expose the Docker TCP socket? <y/N> " prompt
if [[ "${prompt,,}" =~ ^(y|yes)$ ]]; then
msg_info "Exposing Docker TCP socket"
$STD mkdir -p /etc/docker
$STD echo '{ "hosts": ["unix:///var/run/docker.sock", "tcp://0.0.0.0:2375"] }' >/etc/docker/daemon.json
if [[ -n "${var_docker_socket:-}" ]]; then
prompt="$var_docker_socket"
else
read -r -p "${TAB3}Would you like to expose the Docker TCP socket? <y/N> " prompt
fi
case "${prompt,,}" in
y | yes | a | all) socket="tcp://0.0.0.0:2375" ;;
l | local) socket="tcp://127.0.0.1:2375" ;;
*) socket="" ;;
esac
if [[ -n "$socket" ]]; then
msg_info "Exposing Docker TCP socket on $socket"
mkdir -p /etc/docker
# No $STD here: silent() captures stdout, which left daemon.json empty.
printf '{ "hosts": ["unix:///var/run/docker.sock", "%s"] }\n' "$socket" >/etc/docker/daemon.json
$STD rc-service docker restart
msg_ok "Exposed Docker TCP socket at tcp://+:2375"
msg_ok "Exposed Docker TCP socket on $socket"
fi
}

View File

@@ -38,7 +38,8 @@ rm -f "$DEB_FILE"
echo "$LATEST_VERSION" >~/.emqx
msg_ok "Installed EMQX"
read -r -p "${TAB3}Would you like to disable the EMQX MQ feature? (reduces disk/CPU usage) <y/N> " prompt
prompt="${var_emqx_disable_mq:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to disable the EMQX MQ feature? (reduces disk/CPU usage) <y/N> " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
msg_info "Disabling EMQX MQ feature"
mkdir -p /etc/emqx

View File

@@ -21,7 +21,7 @@ PYTHON_VERSION="3.13" setup_uv
NODE_VERSION="24" setup_nodejs
PG_VERSION="17" PG_MODULES="postgis" setup_postgresql
PG_DB_NAME="enduraindb" PG_DB_USER="endurain" setup_postgresql_db
fetch_and_deploy_codeberg_release "endurain" "endurain-project/endurain" "tarball" "latest" "/opt/endurain"
fetch_and_deploy_gh_release "endurain" "endurain-project/endurain"
msg_info "Setting up Endurain"
cd /opt/endurain

View File

@@ -0,0 +1,49 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ) | Co-Author: 007hacky007
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/FoldingAtHome/fah-client-bastet
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
if [[ -z "${var_fah_token:-}" ]]; then
var_fah_token=$(prompt_password "Folding@home account token (Enter to skip):" "" 120)
fi
if [[ -z "${var_fah_machine_name:-}" ]]; then
var_fah_machine_name=$(prompt_input "Folding@home machine name:" "$(hostname)" 60)
fi
if [[ ${#var_fah_machine_name} -gt 64 || "$var_fah_machine_name" == *[\<\>\;\&\'\"]* ]]; then
msg_warn "Machine name must be 1-64 characters without <>;&'\" - using $(hostname)"
var_fah_machine_name=$(hostname)
fi
msg_info "Configuring Folding@home"
mkdir -p /etc/fah-client
cat <<EOF >/etc/fah-client/config.xml
<config>
<account-token v="${var_fah_token}"/>
<machine-name v="${var_fah_machine_name}"/>
</config>
EOF
msg_ok "Configured Folding@home"
fetch_and_deploy_from_url "https://download.foldingathome.org/releases/public/fah-client/$(arch_resolve "debian-10-64bit" "debian-stable-arm64")/release/latest.deb"
setup_hwaccel "fah-client"
# The client detects GPUs only at startup, so restart it after setup_hwaccel.
msg_info "Starting Folding@home"
systemctl enable -q fah-client
safe_service_restart fah-client
msg_ok "Started Folding@home"
motd_ssh
customize
cleanup_lxc

View File

@@ -15,7 +15,8 @@ update_os
fetch_and_deploy_gh_release "headscale" "juanfont/headscale" "binary"
read -r -p "${TAB3}Would you like to add headscale-admin UI? <y/N> " prompt
prompt="${var_headscale_admin:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add headscale-admin UI? <y/N> " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
fetch_and_deploy_gh_release "headscale-admin" "GoodiesHQ/headscale-admin" "prebuild" "latest" "/opt/headscale-admin" "admin.zip"

View File

@@ -33,16 +33,7 @@ NODE_OPTIONS=${NODE_OPTIONS}
EOF
msg_ok "Configured Service Environment"
msg_warn "WARNING: This script will run an external installer from a third-party source (https://hermes-agent.nousresearch.com/)."
msg_warn "The following code is NOT maintained or audited by our repository."
msg_warn "If you have any doubts or concerns, please review the installer code before proceeding:"
msg_custom "${TAB3}${GATEWAY}${BGN}${CL}" "\e[1;34m" "→ https://hermes-agent.nousresearch.com/install.sh"
echo
read -r -p "${TAB3}Do you want to continue? [y/N]: " CONFIRM
if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
msg_error "Aborted by user. No changes have been made."
exit 10
fi
confirm_external_installer "https://hermes-agent.nousresearch.com/" "https://hermes-agent.nousresearch.com/install.sh"
msg_info "Installing Hermes Agent"
curl -fsSL https://hermes-agent.nousresearch.com/install.sh -o /tmp/hermes-install.sh

View File

@@ -25,6 +25,18 @@ NODE_VERSION=$(curl -s https://raw.githubusercontent.com/homarr-labs/homarr/dev/
setup_nodejs
fetch_and_deploy_gh_release "homarr" "homarr-labs/homarr" "prebuild" "latest" "/opt/homarr" "build-debian-$(arch_resolve).tar.gz"
# v2.3.0's Debian build ships a musl better-sqlite3 (homarr-labs/homarr#7097).
mapfile -t MUSL_MODULES < <(find /opt/homarr -name better_sqlite3.node -exec grep -aqE "ld-musl|libc\.musl" {} \; -print)
if ((${#MUSL_MODULES[@]})); then
msg_info "Replacing musl better-sqlite3 build"
BSQ_VERSION=$(jq -r .version /opt/homarr/node_modules/better-sqlite3/package.json)
curl_with_retry "https://github.com/WiseLibs/better-sqlite3/releases/download/v${BSQ_VERSION}/better-sqlite3-v${BSQ_VERSION}-node-v$(node -p process.versions.modules)-linux-$(arch_resolve "x64" "arm64").tar.gz" /tmp/better-sqlite3.tar.gz
tar -xzf /tmp/better-sqlite3.tar.gz -C /tmp build/Release/better_sqlite3.node
for module in "${MUSL_MODULES[@]}"; do cp /tmp/build/Release/better_sqlite3.node "$module"; done
rm -rf /tmp/better-sqlite3.tar.gz /tmp/build
msg_ok "Replaced musl better-sqlite3 build"
fi
msg_info "Installing Homarr"
mkdir -p /opt/homarr_db
touch /opt/homarr_db/db.sqlite

View File

@@ -13,6 +13,7 @@ setting_up_container
network_check
update_os
RELEASE="v3.3.0"
if lscpu | grep -q 'GenuineIntel'; then
echo ""
echo ""
@@ -33,11 +34,11 @@ if lscpu | grep -q 'GenuineIntel'; then
msg_info "Installing Intel OpenVINO dependencies"
tmp_dir=$(mktemp -d)
$STD pushd "$tmp_dir"
curl_with_retry "https://raw.githubusercontent.com/immich-app/immich/refs/heads/main/machine-learning/Dockerfile" "Dockerfile"
readarray -t INTEL_URLS < <(
sed -n "/intel-[igc|opencl]/p" ./Dockerfile | awk '{print $3}'
sed -n "/libigdgmm12/p" ./Dockerfile | awk '{print $3}'
)
INTEL_SRC="https://raw.githubusercontent.com/immich-app/immich/${RELEASE}/machine-learning"
curl -fsSL "${INTEL_SRC}/scripts/install-intel-runtime.sh" -o ./intel-runtime 2>/dev/null ||
curl_with_retry "${INTEL_SRC}/Dockerfile" "./intel-runtime"
readarray -t INTEL_URLS < <(grep -oE 'https://github\.com/intel/[^[:space:]]+\.deb' ./intel-runtime)
rm -f ./intel-runtime
for url in "${INTEL_URLS[@]}"; do
curl_with_retry "$url" "$(basename "$url")"
done
@@ -353,7 +354,7 @@ ML_DIR="${APP_DIR}/machine-learning"
GEO_DIR="${INSTALL_DIR}/geodata"
mkdir -p {"${APP_DIR}","${UPLOAD_DIR}","${GEO_DIR}","${INSTALL_DIR}"/cache}
fetch_and_deploy_gh_release "Immich" "immich-app/immich" "tarball" "v3.2.4" "$SRC_DIR"
fetch_and_deploy_gh_release "Immich" "immich-app/immich" "tarball" "${RELEASE}" "$SRC_DIR"
PNPM_VERSION="$(jq -r '.packageManager | split("@")[1] | split("+")[0]' ${SRC_DIR}/package.json)"
export COREPACK_ENABLE_DOWNLOAD_PROMPT=0
NODE_VERSION="24" NODE_MODULE="corepack" setup_nodejs
@@ -440,13 +441,16 @@ if [[ -f ~/.openvino ]]; then
msg_ok "Pre-installed Python ${ML_PYTHON}"
msg_info "Installing Intel OpenVINO machine-learning"
for attempt in $(seq 1 3); do
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT -Pnu immich uv sync --extra openvino --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
[[ $attempt -lt 3 ]] && msg_warn "uv sync attempt $attempt failed, retrying..." && sleep 10
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT,UV_CONCURRENT_DOWNLOADS,UV_CONCURRENT_BUILDS,UV_CONCURRENT_INSTALLS -Pnu immich uv sync --extra openvino --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
[[ $attempt -eq 3 ]] && { msg_error "uv sync failed three times, the machine-learning environment was not built"; exit 1; }
# Parallel fetches can trip DNS rate limits (AdGuard, Pi-hole); retry one at a time.
export UV_CONCURRENT_DOWNLOADS=1 UV_CONCURRENT_BUILDS=1 UV_CONCURRENT_INSTALLS=1
msg_warn "uv sync attempt $attempt failed, retrying one download at a time..." && sleep 10
done
patchelf --clear-execstack "${VIRTUAL_ENV}/lib/python3.13/site-packages/onnxruntime/capi/onnxruntime_pybind11_state.cpython-313-$(arch_resolve "x86_64" "aarch64")-linux-gnu.so"
msg_ok "Installed Intel OpenVINO machine-learning"
else
ML_PYTHON="python3.11"
ML_PYTHON="python3.13"
msg_info "Pre-installing Python ${ML_PYTHON} for machine-learning"
for attempt in $(seq 1 3); do
$STD sudo --preserve-env=VIRTUAL_ENV -Pnu immich uv python install "${ML_PYTHON}" && break
@@ -455,8 +459,11 @@ else
msg_ok "Pre-installed Python ${ML_PYTHON}"
msg_info "Installing machine-learning"
for attempt in $(seq 1 3); do
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT -Pnu immich uv sync --extra cpu --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
[[ $attempt -lt 3 ]] && msg_warn "uv sync attempt $attempt failed, retrying..." && sleep 10
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT,UV_CONCURRENT_DOWNLOADS,UV_CONCURRENT_BUILDS,UV_CONCURRENT_INSTALLS -Pnu immich uv sync --extra cpu --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
[[ $attempt -eq 3 ]] && { msg_error "uv sync failed three times, the machine-learning environment was not built"; exit 1; }
# Parallel fetches can trip DNS rate limits (AdGuard, Pi-hole); retry one at a time.
export UV_CONCURRENT_DOWNLOADS=1 UV_CONCURRENT_BUILDS=1 UV_CONCURRENT_INSTALLS=1
msg_warn "uv sync attempt $attempt failed, retrying one download at a time..." && sleep 10
done
msg_ok "Installed machine-learning"
fi
@@ -487,25 +494,12 @@ ln -s "$GEO_DIR" "$APP_DIR"
msg_ok "Installed GeoNames data"
# MickLesk temporary patch for HEIC thumbnail gen
msg_info "Patching media.repository.js"
MEDIA_REPO_JS="/opt/immich/app/dist/repositories/media.repository.js"
if [[ -f "$MEDIA_REPO_JS" ]]; then
python3 - <<'PY'
from pathlib import Path
p = Path('/opt/immich/app/dist/repositories/media.repository.js')
s = p.read_text()
old = "(0, sharp_1.default)(input).metadata()"
new = "(0, sharp_1.default)(input, { unlimited: true, limitInputPixels: false }).metadata()"
if new in s:
print('hotfix already there')
elif old in s:
p.write_text(s.replace(old, new, 1))
print('hotfix applied')
else:
print('pattern not found, skipped')
PY
if grep -qF "(0, sharp_1.default)(input).metadata()" "$MEDIA_REPO_JS" 2>/dev/null; then
msg_info "Patching media.repository.js"
sed -i '0,/(0, sharp_1\.default)(input)\.metadata()/s//(0, sharp_1.default)(input, { unlimited: true, limitInputPixels: false }).metadata()/' "$MEDIA_REPO_JS"
msg_ok "Patched media.repository.js"
fi
msg_ok "Patched media.repository.js"
mkdir -p /var/log/immich
touch /var/log/immich/{web.log,ml.log}
@@ -536,6 +530,7 @@ MACHINE_LEARNING_CACHE_FOLDER=${INSTALL_DIR}/cache
## - inference speed while reducing accuracy
## - Default is FP32
# MACHINE_LEARNING_OPENVINO_PRECISION=FP16
MACHINE_LEARNING_MODEL_REVISION=v2
IMMICH_MEDIA_LOCATION=${UPLOAD_DIR}
EOF

View File

@@ -50,7 +50,8 @@ else
fi
msg_ok "Installed InfluxDB"
read -r -p "${TAB3}Would you like to add Telegraf? <y/N> " prompt
prompt="${var_influxdb_telegraf:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add Telegraf? <y/N> " prompt
if [[ "${prompt,,}" =~ ^(y|yes)$ ]]; then
msg_info "Installing Telegraf"
$STD apt install -y telegraf

View File

@@ -17,16 +17,7 @@ msg_info "Installing Dependencies"
$STD apt install -y ca-certificates
msg_ok "Installed Dependencies"
msg_warn "WARNING: This script will run an external installer from a third-party source (https://iobroker.net/)."
msg_warn "The following code is NOT maintained or audited by our repository."
msg_warn "If you have any doubts or concerns, please review the installer code before proceeding:"
msg_custom "${TAB3}${GATEWAY}${BGN}${CL}" "\e[1;34m" "→ https://iobroker.net/install.sh"
echo
read -r -p "${TAB3}Do you want to continue? [y/N]: " CONFIRM
if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
msg_error "Aborted by user. No changes have been made."
exit 10
fi
confirm_external_installer "https://iobroker.net/" "https://iobroker.net/install.sh"
NODE_VERSION="24" NPM_VERSION="11" setup_nodejs

View File

@@ -13,7 +13,7 @@ setting_up_container
network_check
update_os
NODE_VERSION="22" NODE_MODULE="yarn" setup_nodejs
NODE_VERSION="24" NODE_MODULE="yarn" setup_nodejs
fetch_and_deploy_gh_release "jotty" "fccview/jotty" "prebuild" "latest" "/opt/jotty" "jotty_*_prebuild.tar.gz"
msg_info "Setup jotty"

View File

@@ -56,16 +56,7 @@ if [[ -z "$KASM_VERSION" ]] || [[ -z "$KASM_URL" ]]; then
fi
msg_ok "Detected Kasm Workspaces version $KASM_VERSION"
msg_warn "WARNING: This script will run an external installer from a third-party source (https://www.kasmweb.com/)."
msg_warn "The following code is NOT maintained or audited by our repository."
msg_warn "If you have any doubts or concerns, please review the installer code before proceeding:"
msg_custom "${TAB3}${GATEWAY}${BGN}${CL}" "\e[1;34m" "→ install.sh inside tar.gz $KASM_URL"
echo
read -r -p "${TAB3}Do you want to continue? [y/N]: " CONFIRM
if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
msg_error "Aborted by user. No changes have been made."
exit 10
fi
confirm_external_installer "https://www.kasmweb.com/" "install.sh inside tar.gz $KASM_URL"
msg_info "Installing Kasm Workspaces"
curl_download "/opt/kasm_release_${KASM_VERSION}.tar.gz" "$KASM_URL"

View File

@@ -20,15 +20,14 @@ $STD apt install -y \
openssl \
ffmpeg \
python3 \
python3-pip \
python3-dev \
python3-numpy \
redis-server
msg_ok "Installed Dependencies"
PG_VERSION="16" PG_MODULES="pgvector" setup_postgresql
PG_DB_NAME="kima" PG_DB_USER="kima" PG_DB_GRANT_SUPERUSER="true" setup_postgresql_db
NODE_VERSION="24" setup_nodejs
PYTHON_VERSION="3.13" setup_uv
msg_info "Configuring Redis"
systemctl enable -q --now redis-server
@@ -37,8 +36,8 @@ msg_ok "Configured Redis"
fetch_and_deploy_gh_release "kima-hub" "Chevron7Locked/kima-hub" "tarball"
msg_info "Installing Python Dependencies"
export PIP_BREAK_SYSTEM_PACKAGES=1
$STD pip3 install --no-cache-dir \
$STD uv venv --python 3.13 /opt/kima-hub/venv
$STD uv pip install --no-cache --python /opt/kima-hub/venv \
tensorflow \
essentia-tensorflow \
redis \
@@ -174,7 +173,7 @@ Environment=BATCH_SIZE=10
Environment=SLEEP_INTERVAL=5
Environment=NUM_WORKERS=2
Environment=THREADS_PER_WORKER=1
ExecStart=/usr/bin/python3 /opt/kima-hub/services/audio-analyzer/analyzer.py
ExecStart=/opt/kima-hub/venv/bin/python /opt/kima-hub/services/audio-analyzer/analyzer.py
Restart=on-failure
RestartSec=10
@@ -197,7 +196,7 @@ Environment=BACKEND_URL=http://localhost:3006
Environment=MUSIC_PATH=/music
Environment=SLEEP_INTERVAL=5
Environment=NUM_WORKERS=1
ExecStart=/usr/bin/python3 /opt/kima-hub/services/audio-analyzer-clap/analyzer.py
ExecStart=/opt/kima-hub/venv/bin/python /opt/kima-hub/services/audio-analyzer-clap/analyzer.py
Restart=on-failure
RestartSec=10

View File

@@ -2,7 +2,7 @@
# Copyright (c) 2021-2026 community-scripts ORG
# Author: (AminGholizad)
# License: MIT | https://github.com/AminGholizad/ProxmoxVED/raw/main/LICENSE
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/PanSalut/Koffan
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"

View File

@@ -24,7 +24,8 @@ PG_VERSION="16" setup_postgresql
RUST_CRATES="monolith" setup_rust
PG_DB_NAME="linkwardendb" PG_DB_USER="linkwarden" setup_postgresql_db
read -r -p "${TAB3}Would you like to add Adminer? <y/N> " prompt
prompt="${var_linkwarden_adminer:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add Adminer? <y/N> " prompt
if [[ "${prompt,,}" =~ ^(y|yes)$ ]]; then
setup_adminer
fi

View File

@@ -28,16 +28,7 @@ export HOME=/opt/livebook
$STD adduser --system --group --home /opt/livebook --shell /bin/bash livebook
msg_ok "Created livebook user"
msg_warn "WARNING: This script will run an external installer from a third-party source (https://elixir-lang.org)."
msg_warn "The following code is NOT maintained or audited by our repository."
msg_warn "If you have any doubts or concerns, please review the installer code before proceeding:"
msg_custom "${TAB3}${GATEWAY}${BGN}${CL}" "\e[1;34m" "→ https://elixir-lang.org/install.sh"
echo
read -r -p "${TAB3}Do you want to continue? [y/N]: " CONFIRM
if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
msg_error "Aborted by user. No changes have been made."
exit 10
fi
confirm_external_installer "https://elixir-lang.org" "https://elixir-lang.org/install.sh"
curl -fsSO https://elixir-lang.org/install.sh
$STD sh install.sh elixir@latest otp@latest

View File

@@ -0,0 +1,92 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: Bryan Lieberman (BryanCLieberman)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://localai.io
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
msg_info "Installing Dependencies"
$STD apt install -y \
libgomp1 \
libopenblas0
msg_ok "Installed Dependencies"
setup_hwaccel
var_port="${var_port:-8080}"
var_auth="${var_auth:-no}"
var_api_key="${var_api_key:-}"
if [[ "$var_auth" == "yes" ]]; then
setup_postgresql
PG_DB_NAME="localai" PG_DB_USER="localai" setup_postgresql_db
fi
fetch_and_deploy_gh_release "localai" "mudler/LocalAI" "singlefile" "latest" "/opt/localai" "local-ai-v*-linux-$(arch_resolve amd64 arm64)"
msg_info "Configuring LocalAI"
mkdir -p /opt/localai_data/models /opt/localai_data/backends
cat <<EOF >/opt/localai.env
LOCALAI_ADDRESS=0.0.0.0:${var_port}
LOCALAI_DATA_PATH=/opt/localai_data
LOCALAI_MODELS_PATH=/opt/localai_data/models
LOCALAI_BACKENDS_PATH=/opt/localai_data/backends
LOCALAI_LOG_LEVEL=info
EOF
# LocalAI refuses to start on a wildcard bind with nothing to identify callers,
# and binding the wildcard is what makes the container reachable at all.
if [[ "$var_auth" == "yes" ]]; then
cat <<EOF >>/opt/localai.env
LOCALAI_AUTH=true
LOCALAI_AUTH_DATABASE_URL=postgres://${PG_DB_USER}:${PG_DB_PASS}@localhost/${PG_DB_NAME}
LOCALAI_REGISTRATION_MODE=approval
EOF
fi
# A static key grants admin access on its own, so when it is the only thing
# guarding the API, generate one rather than leaving the server open.
if [[ -z "$var_api_key" && "$var_auth" != "yes" ]]; then
var_api_key="sk-$(openssl rand -hex 24)"
{
echo "LocalAI Credentials"
echo "API Key: ${var_api_key}"
} >>~/localai.creds
fi
if [[ -n "$var_api_key" ]]; then
echo "LOCALAI_API_KEY=${var_api_key}" >>/opt/localai.env
else
echo "#LOCALAI_API_KEY=" >>/opt/localai.env
fi
chmod 600 /opt/localai.env
msg_ok "Configured LocalAI"
msg_info "Creating Service"
cat <<EOF >/etc/systemd/system/localai.service
[Unit]
Description=LocalAI Server
Wants=network-online.target
After=network-online.target
[Service]
Type=simple
User=root
WorkingDirectory=/opt/localai
EnvironmentFile=/opt/localai.env
ExecStart=/opt/localai/localai run
Restart=on-failure
RestartSec=10
[Install]
WantedBy=multi-user.target
EOF
systemctl enable -q --now localai
msg_ok "Created Service"
motd_ssh
customize
cleanup_lxc

View File

@@ -21,7 +21,8 @@ setup_deb_based() {
sed -i 's/^bind-address/#bind-address/g' /etc/mysql/mariadb.conf.d/50-server.cnf
msg_ok "Setup MariaDB"
read -r -p "${TAB3}Would you like to add PhpMyAdmin? <y/N> " prompt
prompt="${var_mariadb_phpmyadmin:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add PhpMyAdmin? <y/N> " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
msg_info "Installing phpMyAdmin"
$STD apt install -y \
@@ -58,7 +59,8 @@ setup_alpine() {
$STD rc-service mariadb start
msg_ok "MariaDB Configured"
read -r -p "${TAB3}Would you like to install Adminer with lighttpd? <y/N>: " prompt
prompt="${var_mariadb_adminer:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to install Adminer with lighttpd? <y/N>: " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
msg_info "Installing Adminer and dependencies"
$STD apk add --no-cache \

View File

@@ -13,16 +13,7 @@ setting_up_container
network_check
update_os
msg_warn "WARNING: This script will run an external installer from a third-party source (https://mattermost.com/)."
msg_warn "The following code is NOT maintained or audited by our repository."
msg_warn "If you have any doubts or concerns, please review the installer code before proceeding:"
msg_custom "${TAB3}${GATEWAY}${BGN}${CL}" "\e[1;34m" "→ https://deb.packages.mattermost.com/repo-setup.sh"
echo
read -r -p "${TAB3}Do you want to continue? [y/N]: " CONFIRM
if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
msg_error "Aborted by user. No changes have been made."
exit 10
fi
confirm_external_installer "https://mattermost.com/" "https://deb.packages.mattermost.com/repo-setup.sh"
PG_VERSION="16" setup_postgresql

View File

@@ -15,7 +15,8 @@ update_os
MEILISEARCH_BIND="0.0.0.0:7700" setup_meilisearch
read -r -p "${TAB3}Do you want add meilisearch-ui? [y/n]: " prompt
prompt="${var_meilisearch_ui:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Do you want add meilisearch-ui? [y/n]: " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
NODE_VERSION="22" NODE_MODULE="pnpm@latest" setup_nodejs
fetch_and_deploy_gh_release "meilisearch-ui" "riccox/meilisearch-ui" "tarball"

View File

@@ -13,16 +13,7 @@ setting_up_container
network_check
update_os
msg_warn "WARNING: This script will run an external installer from a third-party source (https://nextcloudpi.com/)."
msg_warn "The following code is NOT maintained or audited by our repository."
msg_warn "If you have any doubts or concerns, please review the installer code before proceeding:"
msg_custom "${TAB3}${GATEWAY}${BGN}${CL}" "\e[1;34m" "→ https://raw.githubusercontent.com/nextcloud/nextcloudpi/master/install.sh"
echo
read -r -p "${TAB3}Do you want to continue? [y/N]: " CONFIRM
if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
msg_error "Aborted by user. No changes have been made."
exit 10
fi
confirm_external_installer "https://nextcloudpi.com/" "https://raw.githubusercontent.com/nextcloud/nextcloudpi/master/install.sh"
msg_info "Making ssh.service reloads behave like restarts"
mkdir -p /etc/systemd/system/ssh.service.d

View File

@@ -64,7 +64,7 @@ $STD sudo -u cool coolconfig set-admin-password --user=admin --password="$COOLPA
echo "$COOLPASS" >~/.coolpass
msg_ok "Installed Collabora Online"
fetch_and_deploy_gh_release "OpenCloud" "opencloud-eu/opencloud" "singlefile" "v7.4.0" "/usr/bin" "opencloud-*-linux-$(arch_resolve)"
fetch_and_deploy_gh_release "OpenCloud" "opencloud-eu/opencloud" "singlefile" "v8.1.0" "/usr/bin" "opencloud-*-linux-$(arch_resolve)"
mv /usr/bin/OpenCloud /usr/bin/opencloud
msg_info "Configuring OpenCloud"
@@ -207,7 +207,7 @@ EOF
$STD sudo -u cool coolconfig set ssl.enable false
$STD sudo -u cool coolconfig set ssl.termination true
$STD sudo -u cool coolconfig set ssl.ssl_verification true
sed -i "s|-Policy\">|&frame-ancestors https://${OPENCLOUD_FQDN}|" /etc/coolwsd/coolwsd.xml
$STD sudo -u cool coolconfig set net.frame_ancestors "https://${OPENCLOUD_FQDN}"
useradd -r -M -s /usr/sbin/nologin opencloud
chown -R opencloud:opencloud "$CONFIG_DIR" "$DATA_DIR"
sudo -u opencloud opencloud init --config-path "$CONFIG_DIR" --insecure no

View File

@@ -26,7 +26,8 @@ setup_hwaccel
PYTHON_VERSION="3.12" setup_uv
OTEL_ARGS=()
read -r -p "${TAB3}Would you like to install OpenTelemetry instrumentation packages (requires manual .env configuration)? <y/N> " prompt
prompt="${var_openwebui_otel:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to install OpenTelemetry instrumentation packages (requires manual .env configuration)? <y/N> " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
for pkg in \
opentelemetry-api \
@@ -52,7 +53,8 @@ for attempt in $(seq 1 3); do
done
msg_ok "Installed Open WebUI"
read -r -p "${TAB3}Would you like to add Ollama? <y/N> " prompt
prompt="${var_openwebui_ollama:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add Ollama? <y/N> " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
if [[ "$(arch_resolve)" == "amd64" ]]; then
msg_info "Setting up Intel® Repositories"

View File

@@ -22,13 +22,10 @@ msg_ok "Installed Dependencies"
NODE_VERSION="24" setup_nodejs
PG_VERSION="17" setup_postgresql
PG_DB_NAME="pangolin" PG_DB_USER="pangolin" setup_postgresql_db
PANGOLIN_VERSION="${PANGOLIN_VERSION:-1.23.0}"
fetch_and_deploy_gh_release "pangolin" "fosrl/pangolin" "tarball" "$PANGOLIN_VERSION"
fetch_and_deploy_gh_release "pangolin" "fosrl/pangolin" "tarball"
fetch_and_deploy_gh_release "gerbil" "fosrl/gerbil" "singlefile" "latest" "/usr/bin" "gerbil_linux_$(arch_resolve)"
fetch_and_deploy_gh_release "traefik" "traefik/traefik" "prebuild" "latest" "/usr/bin" "traefik_v*_linux_$(arch_resolve).tar.gz"
# Read the variable first and prompt only when it is unset, so the install can
# be supplied up front. Same convention as install/forgejo-runner-install.sh.
pango_url="${var_pangolin_url:-}"
if [[ -z "$pango_url" ]]; then
read -rp "${TAB3}Enter your Pangolin URL (ex: https://pangolin.example.com): " pango_url

View File

@@ -46,8 +46,21 @@ msg_info "Configuring Paperclip"
PAPERCLIP_HOME="/opt/paperclip-data"
PAPERCLIP_CONFIG="${PAPERCLIP_HOME}/instances/default/config.json"
mkdir -p /opt/paperclip-data
mkdir -p /root/.claude /root/.codex
PAPERCLIP_USER="${var_paperclip_user:-paperclip}"
# Claude Code refuses --dangerously-skip-permissions as root, so run as a dedicated user
if [[ "$PAPERCLIP_USER" == "root" || ! "$PAPERCLIP_USER" =~ ^[a-z_][a-z0-9_-]{0,31}$ ]]; then
msg_error "Invalid var_paperclip_user '${PAPERCLIP_USER}' (must be a non-root lowercase Linux username)"
exit 1
fi
PAPERCLIP_USER_HOME="/home/${PAPERCLIP_USER}"
id -u "$PAPERCLIP_USER" &>/dev/null || useradd -m -d "$PAPERCLIP_USER_HOME" -s /bin/bash "$PAPERCLIP_USER"
if [[ -n "${var_paperclip_pass:-}" ]]; then
printf '%s:%s\n' "$PAPERCLIP_USER" "$var_paperclip_pass" | chpasswd
else
passwd -l "$PAPERCLIP_USER" &>/dev/null
fi
unset var_paperclip_pass
mkdir -p /opt/paperclip-data "${PAPERCLIP_USER_HOME}/.claude" "${PAPERCLIP_USER_HOME}/.codex"
BETTER_AUTH_SECRET=$(openssl rand -hex 32)
cat <<EOF >/opt/paperclip-ai/.env
DATABASE_URL=postgresql://${PG_DB_USER}:${PG_DB_PASS}@127.0.0.1:5432/${PG_DB_NAME}
@@ -62,11 +75,13 @@ PAPERCLIP_DEPLOYMENT_EXPOSURE=private
PAPERCLIP_PUBLIC_URL=http://${LOCAL_IP}:3100
BETTER_AUTH_SECRET=${BETTER_AUTH_SECRET}
EOF
chmod 600 /opt/paperclip-ai/.env
chown -R "${PAPERCLIP_USER}:${PAPERCLIP_USER}" /opt/paperclip-ai /opt/paperclip-data "$PAPERCLIP_USER_HOME"
msg_ok "Configured Paperclip"
msg_info "Running Database Migrations"
set -a && source /opt/paperclip-ai/.env && set +a
$STD pnpm db:migrate
$STD runuser -u "$PAPERCLIP_USER" -- env HOME="$PAPERCLIP_USER_HOME" pnpm db:migrate
msg_ok "Ran Database Migrations"
msg_info "Bootstrapping Paperclip"
@@ -77,7 +92,8 @@ for PAPERCLIP_ONBOARD_CMD in \
"pnpm paperclipai onboard --yes --bind lan" \
"pnpm paperclipai onboard --yes"; do
rm -f "$PAPERCLIP_ONBOARD_LOG"
setsid env \
setsid runuser -u "$PAPERCLIP_USER" -- env \
HOME="$PAPERCLIP_USER_HOME" \
PAPERCLIP_HOME="$PAPERCLIP_HOME" \
PAPERCLIP_CONFIG="$PAPERCLIP_CONFIG" \
bash -c 'cd /opt/paperclip-ai && exec "$@"' _ $PAPERCLIP_ONBOARD_CMD \
@@ -109,7 +125,8 @@ if [[ ! -f "$PAPERCLIP_CONFIG" ]]; then
fi
if grep -q 'authenticated' $PAPERCLIP_CONFIG; then
pnpm paperclipai auth bootstrap-ceo >"$PAPERCLIP_BOOTSTRAP_LOG" 2>&1 || true
chown "${PAPERCLIP_USER}:${PAPERCLIP_USER}" /opt/paperclip-ai
runuser -u "$PAPERCLIP_USER" -- env HOME="$PAPERCLIP_USER_HOME" bash -c 'cd /opt/paperclip-ai && pnpm paperclipai auth bootstrap-ceo' >"$PAPERCLIP_BOOTSTRAP_LOG" 2>&1 || true
PAPERCLIP_INVITE_URL=$(awk -F'Invite URL: ' '/Invite URL:/ {print $2; exit}' "$PAPERCLIP_BOOTSTRAP_LOG")
PAPERCLIP_INVITE_EXPIRY=$(awk -F'Expires: ' '/Expires:/ {print $2; exit}' "$PAPERCLIP_BOOTSTRAP_LOG")
if [[ -n "$PAPERCLIP_INVITE_URL" ]]; then
@@ -131,6 +148,7 @@ else
fi
rm -f "$PAPERCLIP_ONBOARD_LOG" "$PAPERCLIP_BOOTSTRAP_LOG"
msg_ok "Bootstrapped Paperclip"
echo -e "${INFO}${YW} Authenticate Claude Code and Codex as the service user: ${BGN}su - ${PAPERCLIP_USER}${CL}"
msg_info "Creating Service"
cat <<EOF >/etc/systemd/system/paperclip.service
@@ -141,12 +159,13 @@ Requires=postgresql.service
[Service]
Type=simple
User=root
User=${PAPERCLIP_USER}
Group=${PAPERCLIP_USER}
WorkingDirectory=/opt/paperclip-ai
EnvironmentFile=/opt/paperclip-ai/.env
Environment=HOME=/root
Environment=CODEX_HOME=/root/.codex
Environment=PATH=/root/.local/bin:/usr/local/bin:/usr/bin:/bin
Environment=HOME=${PAPERCLIP_USER_HOME}
Environment=CODEX_HOME=${PAPERCLIP_USER_HOME}/.codex
Environment=PATH=${PAPERCLIP_USER_HOME}/.local/bin:/usr/local/bin:/usr/bin:/bin
Environment=DISABLE_AUTOUPDATER=1
ExecStart=/usr/bin/env pnpm paperclipai run
Restart=on-failure

View File

@@ -163,7 +163,8 @@ EOF
systemctl enable -q --now paperless-webserver paperless-scheduler paperless-task-queue paperless-consumer
msg_ok "Created Services"
read -r -p "${TAB3}Would you like to add Adminer? <y/N> " prompt
prompt="${var_paperless_ngx_adminer:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add Adminer? <y/N> " prompt
if [[ "${prompt,,}" =~ ^(y|yes)$ ]]; then
setup_adminer
fi

View File

@@ -13,16 +13,7 @@ setting_up_container
network_check
update_os
msg_warn "WARNING: This script will run an external installer from a third-party source (https://pi-hole.net/)."
msg_warn "The following code is NOT maintained or audited by our repository."
msg_warn "If you have any doubts or concerns, please review the installer code before proceeding:"
msg_custom "${TAB3}${GATEWAY}${BGN}${CL}" "\e[1;34m" "→ https://install.pi-hole.net"
echo
read -r -p "${TAB3}Do you want to continue? [y/N]: " CONFIRM
if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
msg_error "Aborted by user. No changes have been made."
exit 10
fi
confirm_external_installer "https://pi-hole.net/" "https://install.pi-hole.net"
msg_info "Installing Dependencies"
$STD apt install -y ufw
@@ -65,9 +56,11 @@ $STD pihole-FTL --config ntp.sync.interval 0
systemctl restart pihole-FTL.service
msg_ok "Installed Pi-hole"
read -r -p "${TAB3}Would you like to add Unbound? <y/N> " prompt
prompt="${var_pihole_unbound:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add Unbound? <y/N> " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
read -r -p "${TAB3}Unbound is configured as a recursive DNS server by default, would you like it to be configured as a forwarding DNS server (using DNS-over-TLS (DoT)) instead? <y/N> " prompt
prompt="${var_pihole_unbound_dot:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Unbound is configured as a recursive DNS server by default, would you like it to be configured as a forwarding DNS server (using DNS-over-TLS (DoT)) instead? <y/N> " prompt
msg_info "Installing Unbound"
mkdir -p /etc/unbound/unbound.conf.d
cat <<EOF >/etc/unbound/unbound.conf.d/pi-hole.conf

View File

@@ -48,7 +48,8 @@ msg_ok "Installed Podman"
mkdir -p /etc/containers/systemd
read -r -p "${TAB3}Would you like to add Portainer? <y/N> " prompt
prompt="${var_podman_homeassistant_portainer:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add Portainer? <y/N> " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
msg_info "Installing Portainer $PORTAINER_LATEST_VERSION"
podman volume create portainer_data >/dev/null
@@ -75,7 +76,8 @@ EOF
$STD systemctl start portainer
msg_ok "Installed Portainer $PORTAINER_LATEST_VERSION"
else
read -r -p "${TAB3}Would you like to add the Portainer Agent? <y/N> " prompt
prompt="${var_podman_homeassistant_portainer_agent:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add the Portainer Agent? <y/N> " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
msg_info "Installing Portainer agent $PORTAINER_AGENT_LATEST_VERSION"
cat <<EOF >/etc/containers/systemd/portainer-agent.container

View File

@@ -48,7 +48,8 @@ msg_ok "Installed Podman"
mkdir -p /etc/containers/systemd
read -r -p "${TAB3}Would you like to add Portainer? <y/N> " prompt
prompt="${var_podman_portainer:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add Portainer? <y/N> " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
msg_info "Installing Portainer $PORTAINER_LATEST_VERSION"
podman volume create portainer_data >/dev/null
@@ -76,7 +77,8 @@ EOF
$STD systemctl start portainer
msg_ok "Installed Portainer $PORTAINER_LATEST_VERSION"
else
read -r -p "${TAB3}Would you like to add the Portainer Agent? <y/N> " prompt
prompt="${var_podman_portainer_agent:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add the Portainer Agent? <y/N> " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
msg_info "Installing Portainer agent $PORTAINER_AGENT_LATEST_VERSION"
$STD podman pull docker.io/portainer/agent:latest

View File

@@ -124,7 +124,8 @@ EOF
systemctl restart postgresql
msg_ok "Installed PostgreSQL"
read -r -p "${TAB3}Would you like to add Adminer? <y/N> " prompt
prompt="${var_postgresql_adminer:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add Adminer? <y/N> " prompt
if [[ "${prompt,,}" =~ ^(y|yes)$ ]]; then
msg_info "Installing Adminer"
$STD apt install -y adminer
@@ -158,7 +159,8 @@ setup_alpine() {
$STD rc-service postgresql restart
msg_ok "Configured and Restarted PostgreSQL"
read -r -p "${TAB3}Would you like to install Adminer with lighttpd? <y/N>: " prompt
prompt="${var_postgresql_adminer:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to install Adminer with lighttpd? <y/N>: " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
msg_info "Installing Adminer and dependencies"
$STD apk add --no-cache \

View File

@@ -0,0 +1,168 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/jez500/pricebuddy
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
msg_info "Installing Dependencies"
$STD apt install -y \
nginx \
cron \
xvfb
msg_ok "Installed Dependencies"
PHP_VERSION="8.4" PHP_FPM="YES" PHP_MEMORY_LIMIT="2048M" setup_php
setup_composer
NODE_VERSION="22" setup_nodejs
setup_mariadb
MARIADB_DB_NAME="pricebuddy" MARIADB_DB_USER="pricebuddy" setup_mariadb_db
PYTHON_VERSION="3.12" setup_uv
msg_info "Installing Google Chrome"
setup_deb822_repo \
"google-chrome" \
"https://dl.google.com/linux/linux_signing_key.pub" \
"https://dl.google.com/linux/chrome/deb/" \
"stable"
$STD apt install -y google-chrome-stable
# the package adds its own .list for the same repo, which apt rejects next to the deb822 source
rm -f /etc/apt/sources.list.d/google-chrome.list
msg_ok "Installed Google Chrome"
fetch_and_deploy_gh_release "seleniumbase-scrapper" "jez500/seleniumbase-scrapper" "tarball"
msg_info "Setting up SeleniumBase Scrapper"
$STD uv venv --python 3.12 /opt/seleniumbase-scrapper/.venv
# the SeleniumBase release upstream builds and tests its image against
$STD uv pip install --python /opt/seleniumbase-scrapper/.venv/bin/python \
"seleniumbase==$(sed -n 's/^ARG SELENIUMBASE_VERSION=v//p' /opt/seleniumbase-scrapper/Dockerfile)" \
flask \
beautifulsoup4
$STD /opt/seleniumbase-scrapper/.venv/bin/seleniumbase get chromedriver
msg_ok "Set up SeleniumBase Scrapper"
fetch_and_deploy_gh_release "pricebuddy" "jez500/pricebuddy" "tarball"
msg_info "Setting up PriceBuddy"
cd /opt/pricebuddy
cat <<EOF >/opt/pricebuddy/.env
APP_NAME=PriceBuddy
APP_ENV=production
APP_KEY=base64:$(openssl rand -base64 32)
APP_DEBUG=false
APP_URL=http://${LOCAL_IP}
APP_VERSION=$(cat ~/.pricebuddy)
DB_CONNECTION=mariadb
DB_HOST=127.0.0.1
DB_PORT=3306
DB_DATABASE=pricebuddy
DB_USERNAME=pricebuddy
DB_PASSWORD=${MARIADB_DB_PASS}
SCRAPER_BASE_URL=http://127.0.0.1:3000
APP_USER_EMAIL=admin@example.com
APP_USER_PASSWORD=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c16)
EOF
$STD composer install --no-dev --optimize-autoloader --no-interaction
$STD npm install
$STD npm run build
$STD php artisan storage:link
# reads APP_USER_* for the admin via env(), so it has to run before optimize caches the config
$STD php artisan buddy:init-db
$STD php artisan optimize
$STD php artisan icons:cache
chown -R www-data:www-data /opt/pricebuddy
chmod 600 /opt/pricebuddy/.env
msg_ok "Set up PriceBuddy"
msg_info "Configuring Nginx"
PHP_SOCK=$(get_php_fpm_socket)
cat <<EOF >/etc/nginx/sites-available/pricebuddy
server {
listen 80;
server_name _;
root /opt/pricebuddy/public;
index index.php;
charset utf-8;
location / {
try_files \$uri \$uri/ /index.php?\$query_string;
}
location = /favicon.ico { access_log off; log_not_found off; }
location = /robots.txt { access_log off; log_not_found off; }
error_page 404 /index.php;
location ~ \.php\$ {
fastcgi_pass unix:${PHP_SOCK};
fastcgi_param SCRIPT_FILENAME \$realpath_root\$fastcgi_script_name;
include fastcgi_params;
fastcgi_read_timeout 300;
}
location ~ /\.(?!well-known).* {
deny all;
}
}
EOF
nginx_enable_site "pricebuddy"
msg_ok "Configured Nginx"
msg_info "Creating Services"
cat <<EOF >/etc/systemd/system/seleniumbase-scrapper.service
[Unit]
Description=SeleniumBase Scrapper for PriceBuddy
After=network.target
[Service]
Type=simple
User=root
WorkingDirectory=/opt/seleniumbase-scrapper/api
Environment=API_HOST=127.0.0.1
Environment=API_PORT=3000
ExecStart=/opt/seleniumbase-scrapper/.venv/bin/python /opt/seleniumbase-scrapper/api/server.py
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
cat <<EOF >/etc/systemd/system/pricebuddy-worker.service
[Unit]
Description=PriceBuddy Queue Worker
After=network.target mariadb.service
[Service]
Type=simple
User=www-data
Group=www-data
WorkingDirectory=/opt/pricebuddy
ExecStart=/usr/bin/php /opt/pricebuddy/artisan queue:work
Restart=always
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
cat <<EOF >/etc/cron.d/pricebuddy
* * * * * www-data cd /opt/pricebuddy && php artisan schedule:run >/dev/null 2>&1
EOF
systemctl enable -q --now seleniumbase-scrapper pricebuddy-worker
msg_ok "Created Services"
motd_ssh
customize
cleanup_lxc

View File

@@ -58,7 +58,7 @@ Requires=network.target
[Service]
WorkingDirectory=/opt/radicale
ExecStart=/usr/local/bin/uv run -m radicale --config /etc/radicale/config
ExecStart=/usr/local/bin/uv run --extra bcrypt --extra argon2 -m radicale --config /etc/radicale/config
Restart=on-failure
# User=radicale
# Deny other users access to the calendar data

View File

@@ -40,7 +40,8 @@ $STD uv venv --clear /opt/sabnzbd/venv
$STD uv pip install -r /opt/sabnzbd/requirements.txt --python=/opt/sabnzbd/venv/bin/python
msg_ok "Installed SABnzbd"
read -r -p "Would you like to install par2cmdline-turbo? <y/N> " prompt
prompt="${var_sabnzbd_par2_turbo:-}"
[[ -n "$prompt" ]] || read -r -p "Would you like to install par2cmdline-turbo? <y/N> " prompt
if [[ "${prompt,,}" =~ ^(y|yes)$ ]]; then
mv /usr/bin/par2 /usr/bin/par2.old
fetch_and_deploy_gh_release "par2cmdline-turbo" "animetosho/par2cmdline-turbo" "prebuild" "latest" "/usr/bin/" "*-linux-$(arch_resolve).zip"

View File

@@ -17,7 +17,8 @@ fetch_and_deploy_gh_release "silverbullet" "silverbulletmd/silverbullet" "prebui
mkdir -p /opt/silverbullet/space
RUNTIME_API_ENV=""
read -rp "${TAB3}Enable Silverbullet Runtime API? Requires Chromium (~700MB). Uses ~200MB extra RAM. (y/N): " runtime_api_prompt
runtime_api_prompt="${var_silverbullet_runtime_api:-}"
[[ -n "$runtime_api_prompt" ]] || read -rp "${TAB3}Enable Silverbullet Runtime API? Requires Chromium (~700MB). Uses ~200MB extra RAM. (y/N): " runtime_api_prompt
if [[ "${runtime_api_prompt,,}" =~ ^(y|yes)$ ]]; then
msg_info "Installing Chromium for Runtime API"
$STD apt install -y chromium

View File

@@ -36,7 +36,8 @@ sed -i \
-e 's/^.*picture/#&/' /opt/slskd/config/slskd.yml
msg_ok "Configured Slskd"
read -rp "${TAB3}Do you want to install Soularr? y/N " soularr
soularr="${var_slskd_soularr:-}"
[[ -n "$soularr" ]] || read -rp "${TAB3}Do you want to install Soularr? y/N " soularr
if [[ ${soularr,,} =~ ^(y|yes)$ ]]; then
PYTHON_VERSION="3.11" setup_uv
fetch_and_deploy_gh_release "Soularr" "mrusse/soularr" "tarball" "latest" "/opt/soularr"

View File

@@ -34,7 +34,8 @@ msg_ok "Installed Dependencies"
PYTHON_VERSION="3.12" setup_uv
JAVA_VERSION="25" setup_java
if ! read -r -p "${TAB3}Do you want to use Stirling-PDF with Login? (no/n = without Login) [Y/n] " response; then
response="${var_stirling_pdf_login:-}"
if [[ -z "$response" ]] && ! read -r -p "${TAB3}Do you want to use Stirling-PDF with Login? (no/n = without Login) [Y/n] " response; then
# No interactive stdin (EOF): fall back to the no-login install instead of
# silently selecting login, which the -z test below would otherwise do.
response="n"

View File

@@ -20,7 +20,7 @@ $STD apt install -y \
fonts-dejavu-core
msg_ok "Installed Dependencies"
JAVA_VERSION="17" setup_java
JAVA_VERSION="25" setup_java
PG_VERSION="16" setup_postgresql
PG_DB_NAME="thingsboard_db" PG_DB_USER="thingsboard" setup_postgresql_db
fetch_and_deploy_gh_release "thingsboard" "thingsboard/thingsboard" "binary" "latest" "/tmp" "thingsboard-*.deb"

View File

@@ -105,8 +105,9 @@ setup_alpine() {
$STD apk add traefik --repository=https://dl-cdn.alpinelinux.org/alpine/edge/community
msg_ok "Installed Traefik"
read -p "${TAB3}Enable Traefik WebUI (Port 8080)? [y/N]: " enable_webui
if [[ "$enable_webui" =~ ^[Yy]$ ]]; then
enable_webui="${var_traefik_webui:-}"
[[ -n "$enable_webui" ]] || read -p "${TAB3}Enable Traefik WebUI (Port 8080)? [y/N]: " enable_webui
if [[ "${enable_webui,,}" =~ ^(y|yes)$ ]]; then
msg_info "Configuring Traefik WebUI"
sed -i 's/localhost//g' /etc/traefik/traefik.yaml
msg_ok "Configured Traefik WebUI"

View File

@@ -0,0 +1,46 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: Nicolas Pastorello (opastorello)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://tvheadend.org/ | Github: https://github.com/tvheadend/tvheadend
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
setup_deb822_repo \
"tvheadend" \
"https://dl.cloudsmith.io/public/tvheadend/tvheadend/gpg.C6CC06BD69B430C6.key" \
"https://dl.cloudsmith.io/public/tvheadend/tvheadend/deb/debian" \
"$(get_os_info codename)" \
"main"
var_admin_user="${var_admin_user:-admin}"
var_admin_pass="${var_admin_pass:-$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | cut -c1-13)}"
msg_info "Installing Tvheadend"
echo "tvheadend tvheadend/admin_username string ${var_admin_user}" | debconf-set-selections
echo "tvheadend tvheadend/admin_password password ${var_admin_pass}" | debconf-set-selections
$STD apt install -y tvheadend
msg_ok "Installed Tvheadend"
msg_info "Starting Service"
systemctl enable -q --now tvheadend
msg_ok "Started Service"
msg_info "Saving Credentials"
cat <<EOF >~/tvheadend.creds
Tvheadend Admin Credentials
Username: ${var_admin_user}
Password: ${var_admin_pass}
EOF
msg_ok "Saved Credentials"
motd_ssh
customize
cleanup_lxc

View File

@@ -2,7 +2,7 @@
# Copyright (c) 2021-2026 community-scripts ORG
# Author: Joost van den Berg (montagneId)
# License: MIT | https://github.com/montagneid/ProxmoxVED/raw/main/LICENSE
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/umbraco/Umbraco-CMS
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"

View File

@@ -36,9 +36,11 @@ setup_deb_based() {
msg_ok "Installed Valkey"
echo
read -r -p "${TAB3}Enable TLS for Valkey (Sentinel mode does not supported)? [y/N]: " prompt
prompt="${var_valkey_tls:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Enable TLS for Valkey (Sentinel mode does not supported)? [y/N]: " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
read -r -p "${TAB3}Use TLS-only mode (disable TCP port 6379)? [y/N]: " tls_only
tls_only="${var_valkey_tls_only:-}"
[[ -n "$tls_only" ]] || read -r -p "${TAB3}Use TLS-only mode (disable TCP port 6379)? [y/N]: " tls_only
msg_info "Configuring TLS for Valkey..."
create_self_signed_cert "Valkey"

View File

@@ -16,7 +16,8 @@ update_os
fetch_and_deploy_gh_release "versitygw" "versity/versitygw" "binary"
WEBUI_CONF=""
read -rp "Would you like to enable the VersityGW WebGUI (Beta)? (y/N): " webui_prompt
webui_prompt="${var_versitygw_webgui:-}"
[[ -n "$webui_prompt" ]] || read -rp "Would you like to enable the VersityGW WebGUI (Beta)? (y/N): " webui_prompt
if [[ "${webui_prompt,,}" =~ ^(y|yes)$ ]]; then
WEBUI_CONF="\nVGW_WEBUI_PORT=:7071\nVGW_WEBUI_NO_TLS=true"
msg_ok "WebGUI will be enabled on port 7071"

View File

@@ -27,7 +27,8 @@ msg_ok "Got version $victoriametrics_release of VictoriaMetrics"
fetch_and_deploy_gh_release "victoriametrics" "VictoriaMetrics/VictoriaMetrics" "prebuild" "$victoriametrics_release" "/opt/victoriametrics" "$victoriametrics_filename"
fetch_and_deploy_gh_release "vmutils" "VictoriaMetrics/VictoriaMetrics" "prebuild" "$victoriametrics_release" "/opt/victoriametrics" "$vmutils_filename"
read -r -p "${TAB3}Would you like to add VictoriaLogs? <y/N> " prompt
prompt="${var_victoriametrics_logs:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add VictoriaLogs? <y/N> " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
vl_release_json="$(mktemp)"

View File

@@ -33,7 +33,7 @@ msg_ok "Installed wanderer"
msg_info "Installing wanderer plugins"
for plugin in hammerhead komoot strava; do
fetch_and_deploy_gh_release "wanderer-plugin-${plugin}" "open-wanderer/wanderer" "prebuild" "latest" "/opt/wanderer_data/plugins" "wanderer-plugin-${plugin}.tar.gz" || msg_warn "Failed to install wanderer plugin: ${plugin}"
fetch_and_deploy_gh_release "wanderer-plugin-${plugin}" "open-wanderer/wanderer" "prebuild" "latest" "/opt/wanderer_data/plugins/${plugin}" "wanderer-plugin-${plugin}.tar.gz" || msg_warn "Failed to install wanderer plugin: ${plugin}"
done
msg_ok "Installed wanderer plugins"
@@ -49,6 +49,7 @@ PB_URL=${LOCAL_IP}:8090
PUBLIC_POCKETBASE_URL=http://${LOCAL_IP}:8090
PUBLIC_VALHALLA_URL=https://valhalla1.openstreetmap.de
POCKETBASE_ENCRYPTION_KEY=${POCKETBASE_KEY}
POCKETBASE_PROXY_SECRET=$(openssl rand -hex 32)
PB_DB_LOCATION=/opt/wanderer_data/pb_data
MEILI_DB_PATH=/opt/wanderer_data/meili_data
EOF

View File

@@ -15,16 +15,7 @@ update_os
RELEASE=$(get_latest_github_release "wazuh/wazuh" | cut -d. -f1,2)
msg_warn "WARNING: This script will run an external installer from a third-party source (https://wazuh.com/)."
msg_warn "The following code is NOT maintained or audited by our repository."
msg_warn "If you have any doubts or concerns, please review the installer code before proceeding:"
msg_custom "${TAB3}${GATEWAY}${BGN}${CL}" "\e[1;34m" "→ https://packages.wazuh.com/$RELEASE/wazuh-install.sh "
echo
read -r -p "${TAB3}Do you want to continue? [y/N]: " CONFIRM
if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
msg_error "Aborted by user. No changes have been made."
exit 10
fi
confirm_external_installer "https://wazuh.com/" "https://packages.wazuh.com/$RELEASE/wazuh-install.sh"
msg_info "Setup Wazuh"
curl -fsSL https://packages.wazuh.com/$RELEASE/wazuh-install.sh -o wazuh-install.sh

144
install/weblate-install.sh Normal file
View File

@@ -0,0 +1,144 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/WeblateOrg/weblate
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
msg_info "Installing Dependencies"
$STD apt install -y \
build-essential \
pkg-config \
libacl1-dev \
liblz4-dev \
libzstd-dev \
libxxhash-dev \
libssl-dev \
libldap2-dev \
libsasl2-dev \
git \
gettext \
nginx \
valkey-server
msg_ok "Installed Dependencies"
PG_VERSION="17" setup_postgresql
PG_DB_NAME="weblate" PG_DB_USER="weblate" setup_postgresql_db
PYTHON_VERSION="3.14" setup_uv
USE_ORIGINAL_FILENAME=true fetch_and_deploy_gh_release "weblate" "WeblateOrg/weblate" "singlefile" "latest" "/opt/weblate" "weblate-*-py3-none-any.whl"
msg_info "Installing Weblate"
$STD uv venv --python 3.14 /opt/weblate/.venv
$STD uv pip install --python /opt/weblate/.venv/bin/python --compile-bytecode /opt/weblate/weblate-*.whl "weblate[all,wsgi]"
rm -f /opt/weblate/weblate-*.whl
msg_ok "Installed Weblate"
msg_info "Configuring Weblate"
mkdir -p /opt/weblate_data/python/customize /app
# weblate.settings_docker is upstream's env-driven settings; it reads the secret and
# settings-override.py from /app/data and loads the "customize" app from DATA_DIR/python
ln -sfn /opt/weblate_data /app/data
touch /opt/weblate_data/python/customize/{__init__,models}.py
/opt/weblate/.venv/bin/weblate-generate-secret-key >/opt/weblate_data/secret
cat <<EOF >/opt/weblate_data/weblate.env
DJANGO_SETTINGS_MODULE=weblate.settings_docker
PYTHONPATH=/opt/weblate_data/python
WEBLATE_SITE_DOMAIN=${LOCAL_IP}
WEBLATE_DATA_DIR=/opt/weblate_data
WEBLATE_CACHE_DIR=/opt/weblate/cache
WEBLATE_IP_PROXY_HEADER=HTTP_X_FORWARDED_FOR
POSTGRES_HOST=127.0.0.1
POSTGRES_DB=weblate
POSTGRES_USER=weblate
POSTGRES_PASSWORD=${PG_DB_PASS}
REDIS_HOST=127.0.0.1
# Password set for the "admin" account at install; Weblate does not read it
WEBLATE_ADMIN_PASSWORD=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c16)
EOF
chmod 600 /opt/weblate_data/secret /opt/weblate_data/weblate.env
set -a
source /opt/weblate_data/weblate.env
set +a
$STD /opt/weblate/.venv/bin/weblate migrate --noinput
$STD /opt/weblate/.venv/bin/weblate createadmin --password="${WEBLATE_ADMIN_PASSWORD}"
$STD /opt/weblate/.venv/bin/weblate collectstatic --noinput
msg_ok "Configured Weblate"
msg_info "Configuring Nginx"
cat <<EOF >/etc/nginx/sites-available/weblate
server {
listen 80;
server_name _;
client_max_body_size 1000M;
location = /favicon.ico {
alias /opt/weblate/cache/static/favicon.ico;
expires 30d;
}
location /static/ {
alias /opt/weblate/cache/static/;
expires 30d;
}
location / {
proxy_pass http://127.0.0.1:8888;
proxy_set_header Host \$http_host;
proxy_set_header X-Forwarded-For \$remote_addr;
proxy_set_header X-Forwarded-Proto \$scheme;
proxy_read_timeout 3600;
}
}
EOF
nginx_enable_site "weblate"
msg_ok "Configured Nginx"
msg_info "Creating Services"
cat <<EOF >/etc/systemd/system/weblate.service
[Unit]
Description=Weblate
After=network.target postgresql.service valkey-server.service
[Service]
Type=simple
User=root
WorkingDirectory=/opt/weblate_data
EnvironmentFile=/opt/weblate_data/weblate.env
ExecStart=/opt/weblate/.venv/bin/granian --interface wsgi --host 127.0.0.1 --port 8888 --workers 2 --blocking-threads 8 --backlog 128 --backpressure 16 --runtime-mode mt --workers-max-rss 450 --no-ws weblate.wsgi:application
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
cat <<EOF >/etc/systemd/system/weblate-celery.service
[Unit]
Description=Weblate Celery Worker
After=network.target postgresql.service valkey-server.service
[Service]
Type=simple
User=root
WorkingDirectory=/opt/weblate_data
EnvironmentFile=/opt/weblate_data/weblate.env
ExecStart=/opt/weblate/.venv/bin/celery --app=weblate.utils worker --beat --loglevel=info --queues=celery,notify,memory,translate,backup --prefetch-multiplier=1 --concurrency=2
Restart=on-failure
RestartSec=10
[Install]
WantedBy=multi-user.target
EOF
systemctl enable -q --now weblate weblate-celery
msg_ok "Created Services"
motd_ssh
customize
cleanup_lxc

View File

@@ -36,6 +36,9 @@ PHP_SOCK=$(get_php_fpm_socket)
cat <<EOF >/etc/caddy/Caddyfile
:80 {
root * /opt/webtrees
# Caddy ignores data/.htaccess; media must go through webtrees so its privacy rules apply.
@private path /app/* /data/* /modules_v4/* /resources/* /vendor/* /.*
respond @private 403
php_fastcgi unix/${PHP_SOCK}
file_server
encode gzip

View File

@@ -17,7 +17,7 @@ msg_info "Installing Dependencies"
$STD apt install -y git
msg_ok "Installed Dependencies"
NODE_VERSION="24" NODE_MODULE="yarn,node-gyp" setup_nodejs
NODE_VERSION="26" NODE_MODULE="yarn,node-gyp" setup_nodejs
PG_VERSION="17" setup_postgresql
PG_DB_NAME="wiki" PG_DB_USER="wikijs_user" PG_DB_EXTENSIONS="pg_trgm" setup_postgresql_db
fetch_and_deploy_gh_release "wikijs" "requarks/wiki" "prebuild" "latest" "/opt/wikijs" "wiki-js.tar.gz"

View File

@@ -24,7 +24,8 @@ setup_deb_based() {
$STD netfilter-persistent reload
msg_ok "Installed WireGuard"
read -r -p "${TAB3}Would you like to add WGDashboard? <y/N> " prompt
prompt="${var_wireguard_wgdashboard:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add WGDashboard? <y/N> " prompt
if [[ "${prompt,,}" =~ ^(y|yes)$ ]]; then
git clone -q https://github.com/WGDashboard/WGDashboard.git /etc/wgdashboard
@@ -109,8 +110,9 @@ EOF
$STD sysctl -p /etc/sysctl.conf
msg_ok "Installed WireGuard"
read -rp "${TAB3}Do you want to install WGDashboard? (y/N): " INSTALL_WGD
if [[ "$INSTALL_WGD" =~ ^[Yy]$ ]]; then
INSTALL_WGD="${var_wireguard_wgdashboard:-}"
[[ -n "$INSTALL_WGD" ]] || read -rp "${TAB3}Do you want to install WGDashboard? (y/N): " INSTALL_WGD
if [[ "${INSTALL_WGD,,}" =~ ^(y|yes)$ ]]; then
msg_info "Installing additional dependencies for WGDashboard"
$STD apk add --no-cache \
python3 \

Some files were not shown because too many files have changed in this diff Show More