Compare commits

..

25 Commits

Author SHA1 Message Date
community-scripts-pr-app[bot]
111a281b3e Update CHANGELOG.md (#17743)
Some checks are pending
Create Changelog Pull Request / update-changelog-pull-request (push) Waiting to run
Set state to is_deleted in pocketbase / delete-pocketbase-entry (push) Waiting to run
Sync ct/install to Incus / dispatch (push) Waiting to run
Update script timestamp on .sh changes / update-script-timestamp (push) Waiting to run
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-07 12:06:30 +00:00
samvandenbossche
b755ec70d5 paperclip: run service as a dedicated non-root user (#17707)
Claude Code refuses --dangerously-skip-permissions as root, which blocked
Paperclip onboarding. Run onboarding and the systemd service as a
non-root user (var_paperclip_user, default paperclip) with an optional
var_paperclip_pass (account locked if unset). Existing installs are
migrated on update.

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-07 14:06:14 +02:00
community-scripts-pr-app[bot]
beff70719f Update CHANGELOG.md (#17742)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-07 12:06:00 +00:00
Sim Kai Long
cec9f13da1 OpenCloud: bump to v8.1.0, rebuild search index on upgrade (#17710)
v8 changes the search index format; existing files are not found by
search until the index is rebuilt. When updating from 7.x or older, run
the reindex as a transient systemd unit (the CLI cancels the rebuild if
interrupted), wait for it, and report the outcome.
2026-10-07 14:05:30 +02:00
community-scripts-pr-app[bot]
ea59019670 Update CHANGELOG.md (#17739)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-07 06:32:46 +00:00
CerberusStyle
13bfd8aa15 Thingsboard: update Java version from 17 to 25 (#17733)
* Update Java version from 17 to 25 in install script

* Set JAVA_VERSION before checking for gh release

---------

Co-authored-by: CanbiZ (MickLesk) <47820557+MickLesk@users.noreply.github.com>
2026-10-07 08:32:22 +02:00
community-scripts-pr-app[bot]
175bbe9da7 Update CHANGELOG.md (#17737)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-07 05:38:39 +00:00
community-scripts-pr-app[bot]
48706f41d5 Update CHANGELOG.md (#17730)
Some checks failed
Create Changelog Pull Request / update-changelog-pull-request (push) Has been cancelled
Set state to is_deleted in pocketbase / delete-pocketbase-entry (push) Has been cancelled
Sync ct/install to Incus / dispatch (push) Has been cancelled
Update script timestamp on .sh changes / update-script-timestamp (push) Has been cancelled
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 15:39:40 +00:00
community-scripts-pr-app[bot]
017691457a Update CHANGELOG.md (#17729)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 14:29:29 +00:00
community-scripts-pr-app[bot]
17f5ac84e5 Update CHANGELOG.md (#17728)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 14:27:31 +00:00
community-scripts-pr-app[bot]
0b0ad2e9bd Update CHANGELOG.md (#17727)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 14:27:19 +00:00
community-scripts-pr-app[bot]
78a4d809c7 Update CHANGELOG.md (#17726)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 14:26:51 +00:00
CanbiZ (MickLesk)
36078aa896 Webtrees: stop serving data/ and the source folders directly (#17724)
Caddy served all of /opt/webtrees through file_server, so media under
data/media could be fetched by URL without passing webtrees' privacy rules.
webtrees only protects data/ with an .htaccess, which Caddy ignores. Deny the
folders webtrees' own nginx guide keeps private, plus dotfiles.

update_script adds the rule to existing Caddyfiles on every update, not only
when a new release is out, and keeps the old file if the result fails
caddy validate.
2026-10-06 16:26:21 +02:00
community-scripts-pr-app[bot]
69bbf389f3 Update CHANGELOG.md (#17725)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 14:23:09 +00:00
community-scripts-pr-app[bot]
1da0c463ca Update CHANGELOG.md (#17723)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 13:54:15 +00:00
community-scripts-pr-app[bot]
745f88d484 Update CHANGELOG.md (#17722)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 13:53:39 +00:00
community-scripts-pr-app[bot]
0fba89af41 Update CHANGELOG.md (#17720)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 13:31:19 +00:00
community-scripts-pr-app[bot]
2fa0128614 Update CHANGELOG.md (#17719)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 13:24:53 +00:00
community-scripts-pr-app[bot]
efd8a86c2a Update CHANGELOG.md (#17718)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 13:23:14 +00:00
community-scripts-pr-app[bot]
c7257f3f9d Update CHANGELOG.md (#17717)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 11:40:22 +00:00
community-scripts-pr-app[bot]
15263edeaf Update CHANGELOG.md (#17716)
Some checks failed
Create Changelog Pull Request / update-changelog-pull-request (push) Has been cancelled
Set state to is_deleted in pocketbase / delete-pocketbase-entry (push) Has been cancelled
Sync ct/install to Incus / dispatch (push) Has been cancelled
Update script timestamp on .sh changes / update-script-timestamp (push) Has been cancelled
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 11:32:56 +00:00
community-scripts-pr-app[bot]
463d9828d9 Update CHANGELOG.md (#17715)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 11:32:35 +00:00
community-scripts-pr-app[bot]
405d2fa578 Update CHANGELOG.md (#17714)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 11:10:46 +00:00
community-scripts-pr-app[bot]
185ae4fde2 Update CHANGELOG.md (#17712)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 08:49:06 +00:00
push-app-to-main[bot]
bf3fad3984 Add pricebuddy (ct) (#17708)
Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
2026-10-06 10:48:36 +02:00
11 changed files with 426 additions and 13 deletions

View File

@@ -559,6 +559,51 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
</details>
## 2026-10-07
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- paperclip: run as a dedicated non-root user so Claude Code can skip permissions [@samvandenbossche](https://github.com/samvandenbossche) ([#17707](https://github.com/community-scripts/ProxmoxVE/pull/17707))
- Thingsboard: update Java version from 17 to 25 [@CerberusStyle](https://github.com/CerberusStyle) ([#17733](https://github.com/community-scripts/ProxmoxVE/pull/17733))
- #### 💥 Breaking Changes
- OpenCloud: bump to v8.1.0, rebuild search index on upgrade [@SimKaiLong](https://github.com/SimKaiLong) ([#17710](https://github.com/community-scripts/ProxmoxVE/pull/17710))
### 💾 Core
- Keep setup_nodejs alive when the caller's directory is gone [@MickLesk](https://github.com/MickLesk) ([core#114](https://github.com/community-scripts/core/pull/114))
## 2026-10-06
### 🆕 New Scripts
- Pricebuddy ([#17708](https://github.com/community-scripts/ProxmoxVE/pull/17708))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- Webtrees: stop serving data/ and the source folders directly [@MickLesk](https://github.com/MickLesk) ([#17724](https://github.com/community-scripts/ProxmoxVE/pull/17724))
### 💾 Core
- Incus: check the architecture on Incus hosts too [@MickLesk](https://github.com/MickLesk) ([core#113](https://github.com/community-scripts/core/pull/113))
- Incus: Pass the app's var_* settings into Incus containers [@MickLesk](https://github.com/MickLesk) ([core#112](https://github.com/community-scripts/core/pull/112))
- Incus: stub storage_content_check on Incus [@MickLesk](https://github.com/MickLesk) ([core#104](https://github.com/community-scripts/core/pull/104))
- Incus: map Proxmox template versions to Incus image names [@MickLesk](https://github.com/MickLesk) ([core#111](https://github.com/community-scripts/core/pull/111))
- Incus: read storage names from .vars files [@MickLesk](https://github.com/MickLesk) ([core#110](https://github.com/community-scripts/core/pull/110))
- Incus: show the spinner inside containers again [@MickLesk](https://github.com/MickLesk) ([core#109](https://github.com/community-scripts/core/pull/109))
- Incus: set the hostname with sh, so it works before bash is installed [@MickLesk](https://github.com/MickLesk) ([core#102](https://github.com/community-scripts/core/pull/102))
- Incus: reserve a plain address on Incus, leave the gateway to the network [@MickLesk](https://github.com/MickLesk) ([core#101](https://github.com/community-scripts/core/pull/101))
- Incus: Wait for the network on Alpine OS too [@MickLesk](https://github.com/MickLesk) ([core#105](https://github.com/community-scripts/core/pull/105))
- Incus: do not fail the build when hostname -I is missing [@MickLesk](https://github.com/MickLesk) ([core#103](https://github.com/community-scripts/core/pull/103))
- Incus: Fuse always in unprivileged Containers, attach TUN only when container lacks it [@MickLesk](https://github.com/MickLesk) ([core#108](https://github.com/community-scripts/core/pull/108))
- Incus: accept mode=generated [@MickLesk](https://github.com/MickLesk) ([core#106](https://github.com/community-scripts/core/pull/106))
- Incus: pass the full install environment into Incus containers (quoted) [@MickLesk](https://github.com/MickLesk) ([core#107](https://github.com/community-scripts/core/pull/107))
## 2026-10-05
### 🚀 Updated Scripts

View File

@@ -31,8 +31,9 @@ function update_script() {
exit
fi
RELEASE="v7.4.0"
RELEASE="v8.1.0"
if check_for_gh_release "OpenCloud" "opencloud-eu/opencloud" "${RELEASE}" "each release is tested individually before the version is updated. Please do not open issues for this"; then
OLD_VERSION="$(cat ~/.opencloud 2>/dev/null)"
msg_info "Stopping services"
systemctl stop opencloud opencloud-wopi
msg_ok "Stopped services"
@@ -70,6 +71,34 @@ function update_script() {
msg_info "Starting services"
systemctl start opencloud opencloud-wopi
msg_ok "Started services"
if [[ -z "$OLD_VERSION" || "${OLD_VERSION#v}" =~ ^[0-7]\. ]]; then
# The index CLI cancels the rebuild when interrupted, so it runs as its own unit and the
# update only waits for it. Restart covers a search service that is still starting.
msg_info "Rebuilding search index (safe to interrupt, it continues in the background)"
REINDEX_START="$(date '+%Y-%m-%d %H:%M:%S')"
systemctl reset-failed opencloud-reindex &>/dev/null || true
$STD systemd-run --unit=opencloud-reindex --uid=opencloud --gid=opencloud \
-p EnvironmentFile=/etc/opencloud/opencloud.env -p Restart=on-failure -p RestartSec=15 \
-p StartLimitIntervalSec=900 -p StartLimitBurst=20 \
/usr/bin/opencloud search index --all-spaces --force-rescan --insecure
while [[ "$(systemctl show -p ActiveState --value opencloud-reindex)" =~ ^(active|activating)$ ]]; do
sleep 10
done
if [[ "$(systemctl show -p ActiveState --value opencloud-reindex)" == "failed" ]]; then
msg_ok "Stopped waiting for the search index rebuild"
msg_warn "The rebuild did not complete, see: journalctl -u opencloud-reindex"
msg_warn "Retry with: systemctl reset-failed opencloud-reindex; systemd-run --unit=opencloud-reindex \
--uid=opencloud --gid=opencloud -p EnvironmentFile=/etc/opencloud/opencloud.env \
/usr/bin/opencloud search index --all-spaces --force-rescan --insecure"
else
msg_ok "Rebuilt search index"
if journalctl -u opencloud-reindex --since "$REINDEX_START" --no-pager | grep -qE '/[0-9]+ ERROR'; then
msg_warn "Some spaces could not be indexed, see: journalctl -u opencloud-reindex"
fi
msg_warn "Once search finds older files, remove the old index: rm -rf /var/lib/opencloud/search/bleve"
fi
fi
msg_ok "Updated successfully"
fi
exit

View File

@@ -15,6 +15,8 @@ var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-yes}"
var_unprivileged="${var_unprivileged:-1}"
export var_paperclip_user="${var_paperclip_user:-}"
export var_paperclip_pass="${var_paperclip_pass:-}"
header_info "$APP"
variables
@@ -59,9 +61,35 @@ function update_script() {
@openai/codex@latest
msg_ok "Updated Agent CLIs"
# Claude Code refuses --dangerously-skip-permissions as root; migrate existing installs to a dedicated user
PAPERCLIP_USER=$(sed -n 's/^User=//p' /etc/systemd/system/paperclip.service)
if [[ -z "$PAPERCLIP_USER" || "$PAPERCLIP_USER" == "root" ]]; then
PAPERCLIP_USER="${var_paperclip_user:-paperclip}"
if [[ "$PAPERCLIP_USER" == "root" || ! "$PAPERCLIP_USER" =~ ^[a-z_][a-z0-9_-]{0,31}$ ]]; then
msg_error "Invalid var_paperclip_user '${PAPERCLIP_USER}' (must be a non-root lowercase Linux username)"
exit 1
fi
PAPERCLIP_USER_HOME="/home/${PAPERCLIP_USER}"
id -u "$PAPERCLIP_USER" &>/dev/null || useradd -m -d "$PAPERCLIP_USER_HOME" -s /bin/bash "$PAPERCLIP_USER"
passwd -S "$PAPERCLIP_USER" 2>/dev/null | grep -q " P " || passwd -l "$PAPERCLIP_USER" &>/dev/null
mkdir -p "${PAPERCLIP_USER_HOME}/.claude" "${PAPERCLIP_USER_HOME}/.codex"
[[ -d /root/.claude ]] && cp -a /root/.claude/. "${PAPERCLIP_USER_HOME}/.claude/"
[[ -d /root/.codex ]] && cp -a /root/.codex/. "${PAPERCLIP_USER_HOME}/.codex/"
sed -i \
-e "s|^User=.*|User=${PAPERCLIP_USER}\nGroup=${PAPERCLIP_USER}|" \
-e "s|^Environment=HOME=.*|Environment=HOME=${PAPERCLIP_USER_HOME}|" \
-e "s|^Environment=CODEX_HOME=.*|Environment=CODEX_HOME=${PAPERCLIP_USER_HOME}/.codex|" \
-e "s|/root/.local/bin|${PAPERCLIP_USER_HOME}/.local/bin|" \
/etc/systemd/system/paperclip.service
systemctl daemon-reload
fi
PAPERCLIP_USER_HOME=$(getent passwd "$PAPERCLIP_USER" | cut -d: -f6)
chmod 600 /opt/paperclip-ai/.env
chown -R "${PAPERCLIP_USER}:${PAPERCLIP_USER}" /opt/paperclip-ai /opt/paperclip-data "$PAPERCLIP_USER_HOME"
msg_info "Running Database Migrations"
set -a && source /opt/paperclip-ai/.env && set +a
$STD pnpm db:migrate
$STD runuser -u "$PAPERCLIP_USER" -- env HOME="$PAPERCLIP_USER_HOME" bash -c 'cd /opt/paperclip-ai && pnpm db:migrate'
msg_ok "Ran Database Migrations"
msg_info "Starting Service"

106
ct/pricebuddy.sh Normal file
View File

@@ -0,0 +1,106 @@
#!/usr/bin/env bash
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/jez500/pricebuddy
APP="PriceBuddy"
var_tags="${var_tags:-shopping;price-tracker}"
var_cpu="${var_cpu:-2}"
var_ram="${var_ram:-3072}"
var_disk="${var_disk:-10}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-no}" # the bundled scraper runs Google Chrome, which is amd64-only
var_unprivileged="${var_unprivileged:-1}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -d /opt/pricebuddy ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "pricebuddy" "jez500/pricebuddy"; then
msg_info "Stopping PriceBuddy Worker"
systemctl stop pricebuddy-worker
msg_ok "Stopped PriceBuddy Worker"
setup_composer
NODE_VERSION="22" setup_nodejs
create_backup /opt/pricebuddy/.env /opt/pricebuddy/storage
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "pricebuddy" "jez500/pricebuddy" "tarball"
restore_backup
msg_info "Updating PriceBuddy"
cd /opt/pricebuddy
sed -i "s/^APP_VERSION=.*/APP_VERSION=$(cat ~/.pricebuddy)/" .env
$STD composer install --no-dev --optimize-autoloader --no-interaction
$STD npm install
$STD npm run build
$STD php artisan storage:link
$STD php artisan migrate --force
$STD php artisan optimize
$STD php artisan icons:cache
$STD php artisan buddy:regenerate-price-cache
chown -R www-data:www-data /opt/pricebuddy
msg_ok "Updated PriceBuddy"
msg_info "Starting PriceBuddy Worker"
systemctl start pricebuddy-worker
msg_ok "Started PriceBuddy Worker"
msg_ok "Updated successfully!"
fi
if check_for_gh_release "seleniumbase-scrapper" "jez500/seleniumbase-scrapper"; then
msg_info "Stopping SeleniumBase Scrapper"
systemctl stop seleniumbase-scrapper
msg_ok "Stopped SeleniumBase Scrapper"
msg_info "Updating Google Chrome"
apt_update_safe
upgrade_packages_with_retry google-chrome-stable
msg_ok "Updated Google Chrome"
PYTHON_VERSION="3.12" setup_uv
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "seleniumbase-scrapper" "jez500/seleniumbase-scrapper" "tarball"
msg_info "Updating SeleniumBase Scrapper"
$STD uv venv --python 3.12 /opt/seleniumbase-scrapper/.venv
$STD uv pip install --python /opt/seleniumbase-scrapper/.venv/bin/python \
"seleniumbase==$(sed -n 's/^ARG SELENIUMBASE_VERSION=v//p' /opt/seleniumbase-scrapper/Dockerfile)" \
flask \
beautifulsoup4
$STD /opt/seleniumbase-scrapper/.venv/bin/seleniumbase get chromedriver
msg_ok "Updated SeleniumBase Scrapper"
msg_info "Starting SeleniumBase Scrapper"
systemctl start seleniumbase-scrapper
msg_ok "Started SeleniumBase Scrapper"
fi
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}${CL}"
echo -e "${INFO}${YW}Log in as admin@example.com - the password is APP_USER_PASSWORD in /opt/pricebuddy/.env${CL}"

View File

@@ -30,6 +30,7 @@ function update_script() {
exit
fi
JAVA_VERSION="25" setup_java
if check_for_gh_release "thingsboard" "thingsboard/thingsboard"; then
msg_info "Stopping Service"
systemctl stop thingsboard

View File

@@ -31,6 +31,20 @@ function update_script() {
exit
fi
if ! grep -q "@private" /etc/caddy/Caddyfile; then
msg_info "Blocking direct access to webtrees data"
cp /etc/caddy/Caddyfile /etc/caddy/Caddyfile.bak
sed -i '\|root \* /opt/webtrees|a\ @private path /app/* /data/* /modules_v4/* /resources/* /vendor/* /.*\n respond @private 403' /etc/caddy/Caddyfile
if grep -q "@private" /etc/caddy/Caddyfile && caddy validate --config /etc/caddy/Caddyfile &>/dev/null; then
rm -f /etc/caddy/Caddyfile.bak
systemctl reload-or-restart caddy
msg_ok "Blocked direct access to webtrees data"
else
mv /etc/caddy/Caddyfile.bak /etc/caddy/Caddyfile
msg_warn "Could not patch /etc/caddy/Caddyfile - deny /data/ there by hand"
fi
fi
if check_for_gh_release "webtrees" "fisharebest/webtrees"; then
msg_info "Stopping Service"
PHP_VER=$(php -r 'echo PHP_MAJOR_VERSION . "." . PHP_MINOR_VERSION;')

View File

@@ -64,7 +64,7 @@ $STD sudo -u cool coolconfig set-admin-password --user=admin --password="$COOLPA
echo "$COOLPASS" >~/.coolpass
msg_ok "Installed Collabora Online"
fetch_and_deploy_gh_release "OpenCloud" "opencloud-eu/opencloud" "singlefile" "v7.4.0" "/usr/bin" "opencloud-*-linux-$(arch_resolve)"
fetch_and_deploy_gh_release "OpenCloud" "opencloud-eu/opencloud" "singlefile" "v8.1.0" "/usr/bin" "opencloud-*-linux-$(arch_resolve)"
mv /usr/bin/OpenCloud /usr/bin/opencloud
msg_info "Configuring OpenCloud"

View File

@@ -46,8 +46,21 @@ msg_info "Configuring Paperclip"
PAPERCLIP_HOME="/opt/paperclip-data"
PAPERCLIP_CONFIG="${PAPERCLIP_HOME}/instances/default/config.json"
mkdir -p /opt/paperclip-data
mkdir -p /root/.claude /root/.codex
PAPERCLIP_USER="${var_paperclip_user:-paperclip}"
# Claude Code refuses --dangerously-skip-permissions as root, so run as a dedicated user
if [[ "$PAPERCLIP_USER" == "root" || ! "$PAPERCLIP_USER" =~ ^[a-z_][a-z0-9_-]{0,31}$ ]]; then
msg_error "Invalid var_paperclip_user '${PAPERCLIP_USER}' (must be a non-root lowercase Linux username)"
exit 1
fi
PAPERCLIP_USER_HOME="/home/${PAPERCLIP_USER}"
id -u "$PAPERCLIP_USER" &>/dev/null || useradd -m -d "$PAPERCLIP_USER_HOME" -s /bin/bash "$PAPERCLIP_USER"
if [[ -n "${var_paperclip_pass:-}" ]]; then
printf '%s:%s\n' "$PAPERCLIP_USER" "$var_paperclip_pass" | chpasswd
else
passwd -l "$PAPERCLIP_USER" &>/dev/null
fi
unset var_paperclip_pass
mkdir -p /opt/paperclip-data "${PAPERCLIP_USER_HOME}/.claude" "${PAPERCLIP_USER_HOME}/.codex"
BETTER_AUTH_SECRET=$(openssl rand -hex 32)
cat <<EOF >/opt/paperclip-ai/.env
DATABASE_URL=postgresql://${PG_DB_USER}:${PG_DB_PASS}@127.0.0.1:5432/${PG_DB_NAME}
@@ -62,11 +75,13 @@ PAPERCLIP_DEPLOYMENT_EXPOSURE=private
PAPERCLIP_PUBLIC_URL=http://${LOCAL_IP}:3100
BETTER_AUTH_SECRET=${BETTER_AUTH_SECRET}
EOF
chmod 600 /opt/paperclip-ai/.env
chown -R "${PAPERCLIP_USER}:${PAPERCLIP_USER}" /opt/paperclip-ai /opt/paperclip-data "$PAPERCLIP_USER_HOME"
msg_ok "Configured Paperclip"
msg_info "Running Database Migrations"
set -a && source /opt/paperclip-ai/.env && set +a
$STD pnpm db:migrate
$STD runuser -u "$PAPERCLIP_USER" -- env HOME="$PAPERCLIP_USER_HOME" pnpm db:migrate
msg_ok "Ran Database Migrations"
msg_info "Bootstrapping Paperclip"
@@ -77,7 +92,8 @@ for PAPERCLIP_ONBOARD_CMD in \
"pnpm paperclipai onboard --yes --bind lan" \
"pnpm paperclipai onboard --yes"; do
rm -f "$PAPERCLIP_ONBOARD_LOG"
setsid env \
setsid runuser -u "$PAPERCLIP_USER" -- env \
HOME="$PAPERCLIP_USER_HOME" \
PAPERCLIP_HOME="$PAPERCLIP_HOME" \
PAPERCLIP_CONFIG="$PAPERCLIP_CONFIG" \
bash -c 'cd /opt/paperclip-ai && exec "$@"' _ $PAPERCLIP_ONBOARD_CMD \
@@ -109,7 +125,8 @@ if [[ ! -f "$PAPERCLIP_CONFIG" ]]; then
fi
if grep -q 'authenticated' $PAPERCLIP_CONFIG; then
pnpm paperclipai auth bootstrap-ceo >"$PAPERCLIP_BOOTSTRAP_LOG" 2>&1 || true
chown "${PAPERCLIP_USER}:${PAPERCLIP_USER}" /opt/paperclip-ai
runuser -u "$PAPERCLIP_USER" -- env HOME="$PAPERCLIP_USER_HOME" bash -c 'cd /opt/paperclip-ai && pnpm paperclipai auth bootstrap-ceo' >"$PAPERCLIP_BOOTSTRAP_LOG" 2>&1 || true
PAPERCLIP_INVITE_URL=$(awk -F'Invite URL: ' '/Invite URL:/ {print $2; exit}' "$PAPERCLIP_BOOTSTRAP_LOG")
PAPERCLIP_INVITE_EXPIRY=$(awk -F'Expires: ' '/Expires:/ {print $2; exit}' "$PAPERCLIP_BOOTSTRAP_LOG")
if [[ -n "$PAPERCLIP_INVITE_URL" ]]; then
@@ -131,6 +148,7 @@ else
fi
rm -f "$PAPERCLIP_ONBOARD_LOG" "$PAPERCLIP_BOOTSTRAP_LOG"
msg_ok "Bootstrapped Paperclip"
echo -e "${INFO}${YW} Authenticate Claude Code and Codex as the service user: ${BGN}su - ${PAPERCLIP_USER}${CL}"
msg_info "Creating Service"
cat <<EOF >/etc/systemd/system/paperclip.service
@@ -141,12 +159,13 @@ Requires=postgresql.service
[Service]
Type=simple
User=root
User=${PAPERCLIP_USER}
Group=${PAPERCLIP_USER}
WorkingDirectory=/opt/paperclip-ai
EnvironmentFile=/opt/paperclip-ai/.env
Environment=HOME=/root
Environment=CODEX_HOME=/root/.codex
Environment=PATH=/root/.local/bin:/usr/local/bin:/usr/bin:/bin
Environment=HOME=${PAPERCLIP_USER_HOME}
Environment=CODEX_HOME=${PAPERCLIP_USER_HOME}/.codex
Environment=PATH=${PAPERCLIP_USER_HOME}/.local/bin:/usr/local/bin:/usr/bin:/bin
Environment=DISABLE_AUTOUPDATER=1
ExecStart=/usr/bin/env pnpm paperclipai run
Restart=on-failure

View File

@@ -0,0 +1,168 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/jez500/pricebuddy
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
msg_info "Installing Dependencies"
$STD apt install -y \
nginx \
cron \
xvfb
msg_ok "Installed Dependencies"
PHP_VERSION="8.4" PHP_FPM="YES" PHP_MEMORY_LIMIT="2048M" setup_php
setup_composer
NODE_VERSION="22" setup_nodejs
setup_mariadb
MARIADB_DB_NAME="pricebuddy" MARIADB_DB_USER="pricebuddy" setup_mariadb_db
PYTHON_VERSION="3.12" setup_uv
msg_info "Installing Google Chrome"
setup_deb822_repo \
"google-chrome" \
"https://dl.google.com/linux/linux_signing_key.pub" \
"https://dl.google.com/linux/chrome/deb/" \
"stable"
$STD apt install -y google-chrome-stable
# the package adds its own .list for the same repo, which apt rejects next to the deb822 source
rm -f /etc/apt/sources.list.d/google-chrome.list
msg_ok "Installed Google Chrome"
fetch_and_deploy_gh_release "seleniumbase-scrapper" "jez500/seleniumbase-scrapper" "tarball"
msg_info "Setting up SeleniumBase Scrapper"
$STD uv venv --python 3.12 /opt/seleniumbase-scrapper/.venv
# the SeleniumBase release upstream builds and tests its image against
$STD uv pip install --python /opt/seleniumbase-scrapper/.venv/bin/python \
"seleniumbase==$(sed -n 's/^ARG SELENIUMBASE_VERSION=v//p' /opt/seleniumbase-scrapper/Dockerfile)" \
flask \
beautifulsoup4
$STD /opt/seleniumbase-scrapper/.venv/bin/seleniumbase get chromedriver
msg_ok "Set up SeleniumBase Scrapper"
fetch_and_deploy_gh_release "pricebuddy" "jez500/pricebuddy" "tarball"
msg_info "Setting up PriceBuddy"
cd /opt/pricebuddy
cat <<EOF >/opt/pricebuddy/.env
APP_NAME=PriceBuddy
APP_ENV=production
APP_KEY=base64:$(openssl rand -base64 32)
APP_DEBUG=false
APP_URL=http://${LOCAL_IP}
APP_VERSION=$(cat ~/.pricebuddy)
DB_CONNECTION=mariadb
DB_HOST=127.0.0.1
DB_PORT=3306
DB_DATABASE=pricebuddy
DB_USERNAME=pricebuddy
DB_PASSWORD=${MARIADB_DB_PASS}
SCRAPER_BASE_URL=http://127.0.0.1:3000
APP_USER_EMAIL=admin@example.com
APP_USER_PASSWORD=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c16)
EOF
$STD composer install --no-dev --optimize-autoloader --no-interaction
$STD npm install
$STD npm run build
$STD php artisan storage:link
# reads APP_USER_* for the admin via env(), so it has to run before optimize caches the config
$STD php artisan buddy:init-db
$STD php artisan optimize
$STD php artisan icons:cache
chown -R www-data:www-data /opt/pricebuddy
chmod 600 /opt/pricebuddy/.env
msg_ok "Set up PriceBuddy"
msg_info "Configuring Nginx"
PHP_SOCK=$(get_php_fpm_socket)
cat <<EOF >/etc/nginx/sites-available/pricebuddy
server {
listen 80;
server_name _;
root /opt/pricebuddy/public;
index index.php;
charset utf-8;
location / {
try_files \$uri \$uri/ /index.php?\$query_string;
}
location = /favicon.ico { access_log off; log_not_found off; }
location = /robots.txt { access_log off; log_not_found off; }
error_page 404 /index.php;
location ~ \.php\$ {
fastcgi_pass unix:${PHP_SOCK};
fastcgi_param SCRIPT_FILENAME \$realpath_root\$fastcgi_script_name;
include fastcgi_params;
fastcgi_read_timeout 300;
}
location ~ /\.(?!well-known).* {
deny all;
}
}
EOF
nginx_enable_site "pricebuddy"
msg_ok "Configured Nginx"
msg_info "Creating Services"
cat <<EOF >/etc/systemd/system/seleniumbase-scrapper.service
[Unit]
Description=SeleniumBase Scrapper for PriceBuddy
After=network.target
[Service]
Type=simple
User=root
WorkingDirectory=/opt/seleniumbase-scrapper/api
Environment=API_HOST=127.0.0.1
Environment=API_PORT=3000
ExecStart=/opt/seleniumbase-scrapper/.venv/bin/python /opt/seleniumbase-scrapper/api/server.py
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
cat <<EOF >/etc/systemd/system/pricebuddy-worker.service
[Unit]
Description=PriceBuddy Queue Worker
After=network.target mariadb.service
[Service]
Type=simple
User=www-data
Group=www-data
WorkingDirectory=/opt/pricebuddy
ExecStart=/usr/bin/php /opt/pricebuddy/artisan queue:work
Restart=always
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
cat <<EOF >/etc/cron.d/pricebuddy
* * * * * www-data cd /opt/pricebuddy && php artisan schedule:run >/dev/null 2>&1
EOF
systemctl enable -q --now seleniumbase-scrapper pricebuddy-worker
msg_ok "Created Services"
motd_ssh
customize
cleanup_lxc

View File

@@ -20,7 +20,7 @@ $STD apt install -y \
fonts-dejavu-core
msg_ok "Installed Dependencies"
JAVA_VERSION="17" setup_java
JAVA_VERSION="25" setup_java
PG_VERSION="16" setup_postgresql
PG_DB_NAME="thingsboard_db" PG_DB_USER="thingsboard" setup_postgresql_db
fetch_and_deploy_gh_release "thingsboard" "thingsboard/thingsboard" "binary" "latest" "/tmp" "thingsboard-*.deb"

View File

@@ -36,6 +36,9 @@ PHP_SOCK=$(get_php_fpm_socket)
cat <<EOF >/etc/caddy/Caddyfile
:80 {
root * /opt/webtrees
# Caddy ignores data/.htaccess; media must go through webtrees so its privacy rules apply.
@private path /app/* /data/* /modules_v4/* /resources/* /vendor/* /.*
respond @private 403
php_fastcgi unix/${PHP_SOCK}
file_server
encode gzip