mirror of
https://github.com/community-scripts/ProxmoxVE.git
synced 2026-10-07 08:36:26 -04:00
Compare commits
25 Commits
2026-10-05
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
111a281b3e | ||
|
|
b755ec70d5 | ||
|
|
beff70719f | ||
|
|
cec9f13da1 | ||
|
|
ea59019670 | ||
|
|
13bfd8aa15 | ||
|
|
175bbe9da7 | ||
|
|
48706f41d5 | ||
|
|
017691457a | ||
|
|
17f5ac84e5 | ||
|
|
0b0ad2e9bd | ||
|
|
78a4d809c7 | ||
|
|
36078aa896 | ||
|
|
69bbf389f3 | ||
|
|
1da0c463ca | ||
|
|
745f88d484 | ||
|
|
0fba89af41 | ||
|
|
2fa0128614 | ||
|
|
efd8a86c2a | ||
|
|
c7257f3f9d | ||
|
|
15263edeaf | ||
|
|
463d9828d9 | ||
|
|
405d2fa578 | ||
|
|
185ae4fde2 | ||
|
|
bf3fad3984 |
45
CHANGELOG.md
45
CHANGELOG.md
@@ -559,6 +559,51 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
|
||||
|
||||
</details>
|
||||
|
||||
## 2026-10-07
|
||||
|
||||
### 🚀 Updated Scripts
|
||||
|
||||
- #### 🐞 Bug Fixes
|
||||
|
||||
- paperclip: run as a dedicated non-root user so Claude Code can skip permissions [@samvandenbossche](https://github.com/samvandenbossche) ([#17707](https://github.com/community-scripts/ProxmoxVE/pull/17707))
|
||||
- Thingsboard: update Java version from 17 to 25 [@CerberusStyle](https://github.com/CerberusStyle) ([#17733](https://github.com/community-scripts/ProxmoxVE/pull/17733))
|
||||
|
||||
- #### 💥 Breaking Changes
|
||||
|
||||
- OpenCloud: bump to v8.1.0, rebuild search index on upgrade [@SimKaiLong](https://github.com/SimKaiLong) ([#17710](https://github.com/community-scripts/ProxmoxVE/pull/17710))
|
||||
|
||||
### 💾 Core
|
||||
|
||||
- Keep setup_nodejs alive when the caller's directory is gone [@MickLesk](https://github.com/MickLesk) ([core#114](https://github.com/community-scripts/core/pull/114))
|
||||
|
||||
## 2026-10-06
|
||||
|
||||
### 🆕 New Scripts
|
||||
|
||||
- Pricebuddy ([#17708](https://github.com/community-scripts/ProxmoxVE/pull/17708))
|
||||
|
||||
### 🚀 Updated Scripts
|
||||
|
||||
- #### 🐞 Bug Fixes
|
||||
|
||||
- Webtrees: stop serving data/ and the source folders directly [@MickLesk](https://github.com/MickLesk) ([#17724](https://github.com/community-scripts/ProxmoxVE/pull/17724))
|
||||
|
||||
### 💾 Core
|
||||
|
||||
- Incus: check the architecture on Incus hosts too [@MickLesk](https://github.com/MickLesk) ([core#113](https://github.com/community-scripts/core/pull/113))
|
||||
- Incus: Pass the app's var_* settings into Incus containers [@MickLesk](https://github.com/MickLesk) ([core#112](https://github.com/community-scripts/core/pull/112))
|
||||
- Incus: stub storage_content_check on Incus [@MickLesk](https://github.com/MickLesk) ([core#104](https://github.com/community-scripts/core/pull/104))
|
||||
- Incus: map Proxmox template versions to Incus image names [@MickLesk](https://github.com/MickLesk) ([core#111](https://github.com/community-scripts/core/pull/111))
|
||||
- Incus: read storage names from .vars files [@MickLesk](https://github.com/MickLesk) ([core#110](https://github.com/community-scripts/core/pull/110))
|
||||
- Incus: show the spinner inside containers again [@MickLesk](https://github.com/MickLesk) ([core#109](https://github.com/community-scripts/core/pull/109))
|
||||
- Incus: set the hostname with sh, so it works before bash is installed [@MickLesk](https://github.com/MickLesk) ([core#102](https://github.com/community-scripts/core/pull/102))
|
||||
- Incus: reserve a plain address on Incus, leave the gateway to the network [@MickLesk](https://github.com/MickLesk) ([core#101](https://github.com/community-scripts/core/pull/101))
|
||||
- Incus: Wait for the network on Alpine OS too [@MickLesk](https://github.com/MickLesk) ([core#105](https://github.com/community-scripts/core/pull/105))
|
||||
- Incus: do not fail the build when hostname -I is missing [@MickLesk](https://github.com/MickLesk) ([core#103](https://github.com/community-scripts/core/pull/103))
|
||||
- Incus: Fuse always in unprivileged Containers, attach TUN only when container lacks it [@MickLesk](https://github.com/MickLesk) ([core#108](https://github.com/community-scripts/core/pull/108))
|
||||
- Incus: accept mode=generated [@MickLesk](https://github.com/MickLesk) ([core#106](https://github.com/community-scripts/core/pull/106))
|
||||
- Incus: pass the full install environment into Incus containers (quoted) [@MickLesk](https://github.com/MickLesk) ([core#107](https://github.com/community-scripts/core/pull/107))
|
||||
|
||||
## 2026-10-05
|
||||
|
||||
### 🚀 Updated Scripts
|
||||
|
||||
@@ -31,8 +31,9 @@ function update_script() {
|
||||
exit
|
||||
fi
|
||||
|
||||
RELEASE="v7.4.0"
|
||||
RELEASE="v8.1.0"
|
||||
if check_for_gh_release "OpenCloud" "opencloud-eu/opencloud" "${RELEASE}" "each release is tested individually before the version is updated. Please do not open issues for this"; then
|
||||
OLD_VERSION="$(cat ~/.opencloud 2>/dev/null)"
|
||||
msg_info "Stopping services"
|
||||
systemctl stop opencloud opencloud-wopi
|
||||
msg_ok "Stopped services"
|
||||
@@ -70,6 +71,34 @@ function update_script() {
|
||||
msg_info "Starting services"
|
||||
systemctl start opencloud opencloud-wopi
|
||||
msg_ok "Started services"
|
||||
|
||||
if [[ -z "$OLD_VERSION" || "${OLD_VERSION#v}" =~ ^[0-7]\. ]]; then
|
||||
# The index CLI cancels the rebuild when interrupted, so it runs as its own unit and the
|
||||
# update only waits for it. Restart covers a search service that is still starting.
|
||||
msg_info "Rebuilding search index (safe to interrupt, it continues in the background)"
|
||||
REINDEX_START="$(date '+%Y-%m-%d %H:%M:%S')"
|
||||
systemctl reset-failed opencloud-reindex &>/dev/null || true
|
||||
$STD systemd-run --unit=opencloud-reindex --uid=opencloud --gid=opencloud \
|
||||
-p EnvironmentFile=/etc/opencloud/opencloud.env -p Restart=on-failure -p RestartSec=15 \
|
||||
-p StartLimitIntervalSec=900 -p StartLimitBurst=20 \
|
||||
/usr/bin/opencloud search index --all-spaces --force-rescan --insecure
|
||||
while [[ "$(systemctl show -p ActiveState --value opencloud-reindex)" =~ ^(active|activating)$ ]]; do
|
||||
sleep 10
|
||||
done
|
||||
if [[ "$(systemctl show -p ActiveState --value opencloud-reindex)" == "failed" ]]; then
|
||||
msg_ok "Stopped waiting for the search index rebuild"
|
||||
msg_warn "The rebuild did not complete, see: journalctl -u opencloud-reindex"
|
||||
msg_warn "Retry with: systemctl reset-failed opencloud-reindex; systemd-run --unit=opencloud-reindex \
|
||||
--uid=opencloud --gid=opencloud -p EnvironmentFile=/etc/opencloud/opencloud.env \
|
||||
/usr/bin/opencloud search index --all-spaces --force-rescan --insecure"
|
||||
else
|
||||
msg_ok "Rebuilt search index"
|
||||
if journalctl -u opencloud-reindex --since "$REINDEX_START" --no-pager | grep -qE '/[0-9]+ ERROR'; then
|
||||
msg_warn "Some spaces could not be indexed, see: journalctl -u opencloud-reindex"
|
||||
fi
|
||||
msg_warn "Once search finds older files, remove the old index: rm -rf /var/lib/opencloud/search/bleve"
|
||||
fi
|
||||
fi
|
||||
msg_ok "Updated successfully"
|
||||
fi
|
||||
exit
|
||||
|
||||
@@ -15,6 +15,8 @@ var_os="${var_os:-debian}"
|
||||
var_version="${var_version:-13}"
|
||||
var_arm64="${var_arm64:-yes}"
|
||||
var_unprivileged="${var_unprivileged:-1}"
|
||||
export var_paperclip_user="${var_paperclip_user:-}"
|
||||
export var_paperclip_pass="${var_paperclip_pass:-}"
|
||||
|
||||
header_info "$APP"
|
||||
variables
|
||||
@@ -59,9 +61,35 @@ function update_script() {
|
||||
@openai/codex@latest
|
||||
msg_ok "Updated Agent CLIs"
|
||||
|
||||
# Claude Code refuses --dangerously-skip-permissions as root; migrate existing installs to a dedicated user
|
||||
PAPERCLIP_USER=$(sed -n 's/^User=//p' /etc/systemd/system/paperclip.service)
|
||||
if [[ -z "$PAPERCLIP_USER" || "$PAPERCLIP_USER" == "root" ]]; then
|
||||
PAPERCLIP_USER="${var_paperclip_user:-paperclip}"
|
||||
if [[ "$PAPERCLIP_USER" == "root" || ! "$PAPERCLIP_USER" =~ ^[a-z_][a-z0-9_-]{0,31}$ ]]; then
|
||||
msg_error "Invalid var_paperclip_user '${PAPERCLIP_USER}' (must be a non-root lowercase Linux username)"
|
||||
exit 1
|
||||
fi
|
||||
PAPERCLIP_USER_HOME="/home/${PAPERCLIP_USER}"
|
||||
id -u "$PAPERCLIP_USER" &>/dev/null || useradd -m -d "$PAPERCLIP_USER_HOME" -s /bin/bash "$PAPERCLIP_USER"
|
||||
passwd -S "$PAPERCLIP_USER" 2>/dev/null | grep -q " P " || passwd -l "$PAPERCLIP_USER" &>/dev/null
|
||||
mkdir -p "${PAPERCLIP_USER_HOME}/.claude" "${PAPERCLIP_USER_HOME}/.codex"
|
||||
[[ -d /root/.claude ]] && cp -a /root/.claude/. "${PAPERCLIP_USER_HOME}/.claude/"
|
||||
[[ -d /root/.codex ]] && cp -a /root/.codex/. "${PAPERCLIP_USER_HOME}/.codex/"
|
||||
sed -i \
|
||||
-e "s|^User=.*|User=${PAPERCLIP_USER}\nGroup=${PAPERCLIP_USER}|" \
|
||||
-e "s|^Environment=HOME=.*|Environment=HOME=${PAPERCLIP_USER_HOME}|" \
|
||||
-e "s|^Environment=CODEX_HOME=.*|Environment=CODEX_HOME=${PAPERCLIP_USER_HOME}/.codex|" \
|
||||
-e "s|/root/.local/bin|${PAPERCLIP_USER_HOME}/.local/bin|" \
|
||||
/etc/systemd/system/paperclip.service
|
||||
systemctl daemon-reload
|
||||
fi
|
||||
PAPERCLIP_USER_HOME=$(getent passwd "$PAPERCLIP_USER" | cut -d: -f6)
|
||||
chmod 600 /opt/paperclip-ai/.env
|
||||
chown -R "${PAPERCLIP_USER}:${PAPERCLIP_USER}" /opt/paperclip-ai /opt/paperclip-data "$PAPERCLIP_USER_HOME"
|
||||
|
||||
msg_info "Running Database Migrations"
|
||||
set -a && source /opt/paperclip-ai/.env && set +a
|
||||
$STD pnpm db:migrate
|
||||
$STD runuser -u "$PAPERCLIP_USER" -- env HOME="$PAPERCLIP_USER_HOME" bash -c 'cd /opt/paperclip-ai && pnpm db:migrate'
|
||||
msg_ok "Ran Database Migrations"
|
||||
|
||||
msg_info "Starting Service"
|
||||
|
||||
106
ct/pricebuddy.sh
Normal file
106
ct/pricebuddy.sh
Normal file
@@ -0,0 +1,106 @@
|
||||
#!/usr/bin/env bash
|
||||
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
|
||||
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
|
||||
# Copyright (c) 2021-2026 community-scripts ORG
|
||||
# Author: MickLesk (CanbiZ)
|
||||
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||
# Source: https://github.com/jez500/pricebuddy
|
||||
|
||||
APP="PriceBuddy"
|
||||
var_tags="${var_tags:-shopping;price-tracker}"
|
||||
var_cpu="${var_cpu:-2}"
|
||||
var_ram="${var_ram:-3072}"
|
||||
var_disk="${var_disk:-10}"
|
||||
var_os="${var_os:-debian}"
|
||||
var_version="${var_version:-13}"
|
||||
var_arm64="${var_arm64:-no}" # the bundled scraper runs Google Chrome, which is amd64-only
|
||||
var_unprivileged="${var_unprivileged:-1}"
|
||||
|
||||
header_info "$APP"
|
||||
variables
|
||||
color
|
||||
catch_errors
|
||||
|
||||
function update_script() {
|
||||
header_info
|
||||
check_container_storage
|
||||
check_container_resources
|
||||
|
||||
if [[ ! -d /opt/pricebuddy ]]; then
|
||||
msg_error "No ${APP} Installation Found!"
|
||||
exit
|
||||
fi
|
||||
|
||||
if check_for_gh_release "pricebuddy" "jez500/pricebuddy"; then
|
||||
msg_info "Stopping PriceBuddy Worker"
|
||||
systemctl stop pricebuddy-worker
|
||||
msg_ok "Stopped PriceBuddy Worker"
|
||||
|
||||
setup_composer
|
||||
NODE_VERSION="22" setup_nodejs
|
||||
|
||||
create_backup /opt/pricebuddy/.env /opt/pricebuddy/storage
|
||||
|
||||
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "pricebuddy" "jez500/pricebuddy" "tarball"
|
||||
|
||||
restore_backup
|
||||
|
||||
msg_info "Updating PriceBuddy"
|
||||
cd /opt/pricebuddy
|
||||
sed -i "s/^APP_VERSION=.*/APP_VERSION=$(cat ~/.pricebuddy)/" .env
|
||||
$STD composer install --no-dev --optimize-autoloader --no-interaction
|
||||
$STD npm install
|
||||
$STD npm run build
|
||||
$STD php artisan storage:link
|
||||
$STD php artisan migrate --force
|
||||
$STD php artisan optimize
|
||||
$STD php artisan icons:cache
|
||||
$STD php artisan buddy:regenerate-price-cache
|
||||
chown -R www-data:www-data /opt/pricebuddy
|
||||
msg_ok "Updated PriceBuddy"
|
||||
|
||||
msg_info "Starting PriceBuddy Worker"
|
||||
systemctl start pricebuddy-worker
|
||||
msg_ok "Started PriceBuddy Worker"
|
||||
msg_ok "Updated successfully!"
|
||||
fi
|
||||
|
||||
if check_for_gh_release "seleniumbase-scrapper" "jez500/seleniumbase-scrapper"; then
|
||||
msg_info "Stopping SeleniumBase Scrapper"
|
||||
systemctl stop seleniumbase-scrapper
|
||||
msg_ok "Stopped SeleniumBase Scrapper"
|
||||
|
||||
msg_info "Updating Google Chrome"
|
||||
apt_update_safe
|
||||
upgrade_packages_with_retry google-chrome-stable
|
||||
msg_ok "Updated Google Chrome"
|
||||
|
||||
PYTHON_VERSION="3.12" setup_uv
|
||||
|
||||
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "seleniumbase-scrapper" "jez500/seleniumbase-scrapper" "tarball"
|
||||
|
||||
msg_info "Updating SeleniumBase Scrapper"
|
||||
$STD uv venv --python 3.12 /opt/seleniumbase-scrapper/.venv
|
||||
$STD uv pip install --python /opt/seleniumbase-scrapper/.venv/bin/python \
|
||||
"seleniumbase==$(sed -n 's/^ARG SELENIUMBASE_VERSION=v//p' /opt/seleniumbase-scrapper/Dockerfile)" \
|
||||
flask \
|
||||
beautifulsoup4
|
||||
$STD /opt/seleniumbase-scrapper/.venv/bin/seleniumbase get chromedriver
|
||||
msg_ok "Updated SeleniumBase Scrapper"
|
||||
|
||||
msg_info "Starting SeleniumBase Scrapper"
|
||||
systemctl start seleniumbase-scrapper
|
||||
msg_ok "Started SeleniumBase Scrapper"
|
||||
fi
|
||||
exit
|
||||
}
|
||||
|
||||
start
|
||||
build_container
|
||||
description
|
||||
|
||||
msg_ok "Completed Successfully!\n"
|
||||
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
|
||||
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
|
||||
echo -e "${GATEWAY}${BGN}http://${IP}${CL}"
|
||||
echo -e "${INFO}${YW}Log in as admin@example.com - the password is APP_USER_PASSWORD in /opt/pricebuddy/.env${CL}"
|
||||
@@ -30,6 +30,7 @@ function update_script() {
|
||||
exit
|
||||
fi
|
||||
|
||||
JAVA_VERSION="25" setup_java
|
||||
if check_for_gh_release "thingsboard" "thingsboard/thingsboard"; then
|
||||
msg_info "Stopping Service"
|
||||
systemctl stop thingsboard
|
||||
|
||||
@@ -31,6 +31,20 @@ function update_script() {
|
||||
exit
|
||||
fi
|
||||
|
||||
if ! grep -q "@private" /etc/caddy/Caddyfile; then
|
||||
msg_info "Blocking direct access to webtrees data"
|
||||
cp /etc/caddy/Caddyfile /etc/caddy/Caddyfile.bak
|
||||
sed -i '\|root \* /opt/webtrees|a\ @private path /app/* /data/* /modules_v4/* /resources/* /vendor/* /.*\n respond @private 403' /etc/caddy/Caddyfile
|
||||
if grep -q "@private" /etc/caddy/Caddyfile && caddy validate --config /etc/caddy/Caddyfile &>/dev/null; then
|
||||
rm -f /etc/caddy/Caddyfile.bak
|
||||
systemctl reload-or-restart caddy
|
||||
msg_ok "Blocked direct access to webtrees data"
|
||||
else
|
||||
mv /etc/caddy/Caddyfile.bak /etc/caddy/Caddyfile
|
||||
msg_warn "Could not patch /etc/caddy/Caddyfile - deny /data/ there by hand"
|
||||
fi
|
||||
fi
|
||||
|
||||
if check_for_gh_release "webtrees" "fisharebest/webtrees"; then
|
||||
msg_info "Stopping Service"
|
||||
PHP_VER=$(php -r 'echo PHP_MAJOR_VERSION . "." . PHP_MINOR_VERSION;')
|
||||
|
||||
@@ -64,7 +64,7 @@ $STD sudo -u cool coolconfig set-admin-password --user=admin --password="$COOLPA
|
||||
echo "$COOLPASS" >~/.coolpass
|
||||
msg_ok "Installed Collabora Online"
|
||||
|
||||
fetch_and_deploy_gh_release "OpenCloud" "opencloud-eu/opencloud" "singlefile" "v7.4.0" "/usr/bin" "opencloud-*-linux-$(arch_resolve)"
|
||||
fetch_and_deploy_gh_release "OpenCloud" "opencloud-eu/opencloud" "singlefile" "v8.1.0" "/usr/bin" "opencloud-*-linux-$(arch_resolve)"
|
||||
mv /usr/bin/OpenCloud /usr/bin/opencloud
|
||||
|
||||
msg_info "Configuring OpenCloud"
|
||||
|
||||
@@ -46,8 +46,21 @@ msg_info "Configuring Paperclip"
|
||||
PAPERCLIP_HOME="/opt/paperclip-data"
|
||||
PAPERCLIP_CONFIG="${PAPERCLIP_HOME}/instances/default/config.json"
|
||||
|
||||
mkdir -p /opt/paperclip-data
|
||||
mkdir -p /root/.claude /root/.codex
|
||||
PAPERCLIP_USER="${var_paperclip_user:-paperclip}"
|
||||
# Claude Code refuses --dangerously-skip-permissions as root, so run as a dedicated user
|
||||
if [[ "$PAPERCLIP_USER" == "root" || ! "$PAPERCLIP_USER" =~ ^[a-z_][a-z0-9_-]{0,31}$ ]]; then
|
||||
msg_error "Invalid var_paperclip_user '${PAPERCLIP_USER}' (must be a non-root lowercase Linux username)"
|
||||
exit 1
|
||||
fi
|
||||
PAPERCLIP_USER_HOME="/home/${PAPERCLIP_USER}"
|
||||
id -u "$PAPERCLIP_USER" &>/dev/null || useradd -m -d "$PAPERCLIP_USER_HOME" -s /bin/bash "$PAPERCLIP_USER"
|
||||
if [[ -n "${var_paperclip_pass:-}" ]]; then
|
||||
printf '%s:%s\n' "$PAPERCLIP_USER" "$var_paperclip_pass" | chpasswd
|
||||
else
|
||||
passwd -l "$PAPERCLIP_USER" &>/dev/null
|
||||
fi
|
||||
unset var_paperclip_pass
|
||||
mkdir -p /opt/paperclip-data "${PAPERCLIP_USER_HOME}/.claude" "${PAPERCLIP_USER_HOME}/.codex"
|
||||
BETTER_AUTH_SECRET=$(openssl rand -hex 32)
|
||||
cat <<EOF >/opt/paperclip-ai/.env
|
||||
DATABASE_URL=postgresql://${PG_DB_USER}:${PG_DB_PASS}@127.0.0.1:5432/${PG_DB_NAME}
|
||||
@@ -62,11 +75,13 @@ PAPERCLIP_DEPLOYMENT_EXPOSURE=private
|
||||
PAPERCLIP_PUBLIC_URL=http://${LOCAL_IP}:3100
|
||||
BETTER_AUTH_SECRET=${BETTER_AUTH_SECRET}
|
||||
EOF
|
||||
chmod 600 /opt/paperclip-ai/.env
|
||||
chown -R "${PAPERCLIP_USER}:${PAPERCLIP_USER}" /opt/paperclip-ai /opt/paperclip-data "$PAPERCLIP_USER_HOME"
|
||||
msg_ok "Configured Paperclip"
|
||||
|
||||
msg_info "Running Database Migrations"
|
||||
set -a && source /opt/paperclip-ai/.env && set +a
|
||||
$STD pnpm db:migrate
|
||||
$STD runuser -u "$PAPERCLIP_USER" -- env HOME="$PAPERCLIP_USER_HOME" pnpm db:migrate
|
||||
msg_ok "Ran Database Migrations"
|
||||
|
||||
msg_info "Bootstrapping Paperclip"
|
||||
@@ -77,7 +92,8 @@ for PAPERCLIP_ONBOARD_CMD in \
|
||||
"pnpm paperclipai onboard --yes --bind lan" \
|
||||
"pnpm paperclipai onboard --yes"; do
|
||||
rm -f "$PAPERCLIP_ONBOARD_LOG"
|
||||
setsid env \
|
||||
setsid runuser -u "$PAPERCLIP_USER" -- env \
|
||||
HOME="$PAPERCLIP_USER_HOME" \
|
||||
PAPERCLIP_HOME="$PAPERCLIP_HOME" \
|
||||
PAPERCLIP_CONFIG="$PAPERCLIP_CONFIG" \
|
||||
bash -c 'cd /opt/paperclip-ai && exec "$@"' _ $PAPERCLIP_ONBOARD_CMD \
|
||||
@@ -109,7 +125,8 @@ if [[ ! -f "$PAPERCLIP_CONFIG" ]]; then
|
||||
fi
|
||||
|
||||
if grep -q 'authenticated' $PAPERCLIP_CONFIG; then
|
||||
pnpm paperclipai auth bootstrap-ceo >"$PAPERCLIP_BOOTSTRAP_LOG" 2>&1 || true
|
||||
chown "${PAPERCLIP_USER}:${PAPERCLIP_USER}" /opt/paperclip-ai
|
||||
runuser -u "$PAPERCLIP_USER" -- env HOME="$PAPERCLIP_USER_HOME" bash -c 'cd /opt/paperclip-ai && pnpm paperclipai auth bootstrap-ceo' >"$PAPERCLIP_BOOTSTRAP_LOG" 2>&1 || true
|
||||
PAPERCLIP_INVITE_URL=$(awk -F'Invite URL: ' '/Invite URL:/ {print $2; exit}' "$PAPERCLIP_BOOTSTRAP_LOG")
|
||||
PAPERCLIP_INVITE_EXPIRY=$(awk -F'Expires: ' '/Expires:/ {print $2; exit}' "$PAPERCLIP_BOOTSTRAP_LOG")
|
||||
if [[ -n "$PAPERCLIP_INVITE_URL" ]]; then
|
||||
@@ -131,6 +148,7 @@ else
|
||||
fi
|
||||
rm -f "$PAPERCLIP_ONBOARD_LOG" "$PAPERCLIP_BOOTSTRAP_LOG"
|
||||
msg_ok "Bootstrapped Paperclip"
|
||||
echo -e "${INFO}${YW} Authenticate Claude Code and Codex as the service user: ${BGN}su - ${PAPERCLIP_USER}${CL}"
|
||||
|
||||
msg_info "Creating Service"
|
||||
cat <<EOF >/etc/systemd/system/paperclip.service
|
||||
@@ -141,12 +159,13 @@ Requires=postgresql.service
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=root
|
||||
User=${PAPERCLIP_USER}
|
||||
Group=${PAPERCLIP_USER}
|
||||
WorkingDirectory=/opt/paperclip-ai
|
||||
EnvironmentFile=/opt/paperclip-ai/.env
|
||||
Environment=HOME=/root
|
||||
Environment=CODEX_HOME=/root/.codex
|
||||
Environment=PATH=/root/.local/bin:/usr/local/bin:/usr/bin:/bin
|
||||
Environment=HOME=${PAPERCLIP_USER_HOME}
|
||||
Environment=CODEX_HOME=${PAPERCLIP_USER_HOME}/.codex
|
||||
Environment=PATH=${PAPERCLIP_USER_HOME}/.local/bin:/usr/local/bin:/usr/bin:/bin
|
||||
Environment=DISABLE_AUTOUPDATER=1
|
||||
ExecStart=/usr/bin/env pnpm paperclipai run
|
||||
Restart=on-failure
|
||||
|
||||
168
install/pricebuddy-install.sh
Normal file
168
install/pricebuddy-install.sh
Normal file
@@ -0,0 +1,168 @@
|
||||
#!/usr/bin/env bash
|
||||
|
||||
# Copyright (c) 2021-2026 community-scripts ORG
|
||||
# Author: MickLesk (CanbiZ)
|
||||
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||
# Source: https://github.com/jez500/pricebuddy
|
||||
|
||||
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
|
||||
color
|
||||
verb_ip6
|
||||
catch_errors
|
||||
setting_up_container
|
||||
network_check
|
||||
update_os
|
||||
|
||||
msg_info "Installing Dependencies"
|
||||
$STD apt install -y \
|
||||
nginx \
|
||||
cron \
|
||||
xvfb
|
||||
msg_ok "Installed Dependencies"
|
||||
|
||||
PHP_VERSION="8.4" PHP_FPM="YES" PHP_MEMORY_LIMIT="2048M" setup_php
|
||||
setup_composer
|
||||
NODE_VERSION="22" setup_nodejs
|
||||
setup_mariadb
|
||||
MARIADB_DB_NAME="pricebuddy" MARIADB_DB_USER="pricebuddy" setup_mariadb_db
|
||||
PYTHON_VERSION="3.12" setup_uv
|
||||
|
||||
msg_info "Installing Google Chrome"
|
||||
setup_deb822_repo \
|
||||
"google-chrome" \
|
||||
"https://dl.google.com/linux/linux_signing_key.pub" \
|
||||
"https://dl.google.com/linux/chrome/deb/" \
|
||||
"stable"
|
||||
$STD apt install -y google-chrome-stable
|
||||
# the package adds its own .list for the same repo, which apt rejects next to the deb822 source
|
||||
rm -f /etc/apt/sources.list.d/google-chrome.list
|
||||
msg_ok "Installed Google Chrome"
|
||||
|
||||
fetch_and_deploy_gh_release "seleniumbase-scrapper" "jez500/seleniumbase-scrapper" "tarball"
|
||||
|
||||
msg_info "Setting up SeleniumBase Scrapper"
|
||||
$STD uv venv --python 3.12 /opt/seleniumbase-scrapper/.venv
|
||||
# the SeleniumBase release upstream builds and tests its image against
|
||||
$STD uv pip install --python /opt/seleniumbase-scrapper/.venv/bin/python \
|
||||
"seleniumbase==$(sed -n 's/^ARG SELENIUMBASE_VERSION=v//p' /opt/seleniumbase-scrapper/Dockerfile)" \
|
||||
flask \
|
||||
beautifulsoup4
|
||||
$STD /opt/seleniumbase-scrapper/.venv/bin/seleniumbase get chromedriver
|
||||
msg_ok "Set up SeleniumBase Scrapper"
|
||||
|
||||
fetch_and_deploy_gh_release "pricebuddy" "jez500/pricebuddy" "tarball"
|
||||
|
||||
msg_info "Setting up PriceBuddy"
|
||||
cd /opt/pricebuddy
|
||||
cat <<EOF >/opt/pricebuddy/.env
|
||||
APP_NAME=PriceBuddy
|
||||
APP_ENV=production
|
||||
APP_KEY=base64:$(openssl rand -base64 32)
|
||||
APP_DEBUG=false
|
||||
APP_URL=http://${LOCAL_IP}
|
||||
APP_VERSION=$(cat ~/.pricebuddy)
|
||||
|
||||
DB_CONNECTION=mariadb
|
||||
DB_HOST=127.0.0.1
|
||||
DB_PORT=3306
|
||||
DB_DATABASE=pricebuddy
|
||||
DB_USERNAME=pricebuddy
|
||||
DB_PASSWORD=${MARIADB_DB_PASS}
|
||||
|
||||
SCRAPER_BASE_URL=http://127.0.0.1:3000
|
||||
|
||||
APP_USER_EMAIL=admin@example.com
|
||||
APP_USER_PASSWORD=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c16)
|
||||
EOF
|
||||
$STD composer install --no-dev --optimize-autoloader --no-interaction
|
||||
$STD npm install
|
||||
$STD npm run build
|
||||
$STD php artisan storage:link
|
||||
# reads APP_USER_* for the admin via env(), so it has to run before optimize caches the config
|
||||
$STD php artisan buddy:init-db
|
||||
$STD php artisan optimize
|
||||
$STD php artisan icons:cache
|
||||
chown -R www-data:www-data /opt/pricebuddy
|
||||
chmod 600 /opt/pricebuddy/.env
|
||||
msg_ok "Set up PriceBuddy"
|
||||
|
||||
msg_info "Configuring Nginx"
|
||||
PHP_SOCK=$(get_php_fpm_socket)
|
||||
cat <<EOF >/etc/nginx/sites-available/pricebuddy
|
||||
server {
|
||||
listen 80;
|
||||
server_name _;
|
||||
root /opt/pricebuddy/public;
|
||||
|
||||
index index.php;
|
||||
charset utf-8;
|
||||
|
||||
location / {
|
||||
try_files \$uri \$uri/ /index.php?\$query_string;
|
||||
}
|
||||
|
||||
location = /favicon.ico { access_log off; log_not_found off; }
|
||||
location = /robots.txt { access_log off; log_not_found off; }
|
||||
|
||||
error_page 404 /index.php;
|
||||
|
||||
location ~ \.php\$ {
|
||||
fastcgi_pass unix:${PHP_SOCK};
|
||||
fastcgi_param SCRIPT_FILENAME \$realpath_root\$fastcgi_script_name;
|
||||
include fastcgi_params;
|
||||
fastcgi_read_timeout 300;
|
||||
}
|
||||
|
||||
location ~ /\.(?!well-known).* {
|
||||
deny all;
|
||||
}
|
||||
}
|
||||
EOF
|
||||
nginx_enable_site "pricebuddy"
|
||||
msg_ok "Configured Nginx"
|
||||
|
||||
msg_info "Creating Services"
|
||||
cat <<EOF >/etc/systemd/system/seleniumbase-scrapper.service
|
||||
[Unit]
|
||||
Description=SeleniumBase Scrapper for PriceBuddy
|
||||
After=network.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=root
|
||||
WorkingDirectory=/opt/seleniumbase-scrapper/api
|
||||
Environment=API_HOST=127.0.0.1
|
||||
Environment=API_PORT=3000
|
||||
ExecStart=/opt/seleniumbase-scrapper/.venv/bin/python /opt/seleniumbase-scrapper/api/server.py
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
EOF
|
||||
cat <<EOF >/etc/systemd/system/pricebuddy-worker.service
|
||||
[Unit]
|
||||
Description=PriceBuddy Queue Worker
|
||||
After=network.target mariadb.service
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=www-data
|
||||
Group=www-data
|
||||
WorkingDirectory=/opt/pricebuddy
|
||||
ExecStart=/usr/bin/php /opt/pricebuddy/artisan queue:work
|
||||
Restart=always
|
||||
RestartSec=5
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
EOF
|
||||
cat <<EOF >/etc/cron.d/pricebuddy
|
||||
* * * * * www-data cd /opt/pricebuddy && php artisan schedule:run >/dev/null 2>&1
|
||||
EOF
|
||||
systemctl enable -q --now seleniumbase-scrapper pricebuddy-worker
|
||||
msg_ok "Created Services"
|
||||
|
||||
motd_ssh
|
||||
customize
|
||||
cleanup_lxc
|
||||
@@ -20,7 +20,7 @@ $STD apt install -y \
|
||||
fonts-dejavu-core
|
||||
msg_ok "Installed Dependencies"
|
||||
|
||||
JAVA_VERSION="17" setup_java
|
||||
JAVA_VERSION="25" setup_java
|
||||
PG_VERSION="16" setup_postgresql
|
||||
PG_DB_NAME="thingsboard_db" PG_DB_USER="thingsboard" setup_postgresql_db
|
||||
fetch_and_deploy_gh_release "thingsboard" "thingsboard/thingsboard" "binary" "latest" "/tmp" "thingsboard-*.deb"
|
||||
|
||||
@@ -36,6 +36,9 @@ PHP_SOCK=$(get_php_fpm_socket)
|
||||
cat <<EOF >/etc/caddy/Caddyfile
|
||||
:80 {
|
||||
root * /opt/webtrees
|
||||
# Caddy ignores data/.htaccess; media must go through webtrees so its privacy rules apply.
|
||||
@private path /app/* /data/* /modules_v4/* /resources/* /vendor/* /.*
|
||||
respond @private 403
|
||||
php_fastcgi unix/${PHP_SOCK}
|
||||
file_server
|
||||
encode gzip
|
||||
|
||||
Reference in New Issue
Block a user