Compare commits

..

46 Commits

Author SHA1 Message Date
MickLesk
8bc6470c5e Immich: build libvips with JPEG 2000 support
Only the libopenjp2-7 runtime was installed, so meson found no OpenJPEG
and libvips came out without jp2kload. Immich lists .jp2 as supported
and the upstream image builds against libopenjp2-7-dev. Install the
headers, and rebuild libvips on update when it lacks jp2kload, the way
ImageMagick is rebuilt when its LibRaw define is missing.
2026-10-11 16:01:51 +02:00
community-scripts-pr-app[bot]
fb82f7084a Update CHANGELOG.md (#17861)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 13:44:32 +00:00
CanbiZ (MickLesk)
7198d218be Let var_* answer the optional add-on prompts (#17858)
Thirty-six yes/no prompts for optional components in 26 install
scripts could only be answered at the terminal, so an unattended
install stopped at the first one. Each now takes var_<app>_<option>
first and still asks when it is unset. The four conditions that only
matched a single y now take yes as well, since that is what the website
sends.
2026-10-11 15:44:05 +02:00
community-scripts-pr-app[bot]
afdd1560ae Update CHANGELOG.md (#17860)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 13:37:59 +00:00
CanbiZ (MickLesk)
560bd81537 Confirm third-party installers through confirm_external_installer (#17857)
The thirteen install scripts and two update paths that run an external
installer each carried the same warning and y/N read. The core helper
does the same and also takes var_external_installer, so unattended
installs can answer it. Needs community-scripts/core
feat/confirm-external-installer merged first.
2026-10-11 15:37:33 +02:00
community-scripts-pr-app[bot]
33f516930b Update CHANGELOG.md (#17859)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 13:07:05 +00:00
community-scripts-pr-app[bot]
bbcea041e7 Update CHANGELOG.md (#17856)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 12:20:11 +00:00
push-app-to-main[bot]
386bb80e1e Add cinephage (ct) (#17852)
Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
2026-10-11 14:19:42 +02:00
community-scripts-pr-app[bot]
61336cd55e Update CHANGELOG.md (#17855)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 12:18:10 +00:00
CanbiZ (MickLesk)
6b8698fe87 hermesagent: match the relaunched root gateway regardless of interpreter (#17847)
* hermesagent: match the relaunched root gateway regardless of interpreter

Upstream now starts the gateway through its bundled python via runpy, so
the venv-path pattern from #17126 matched nothing and the root gateway
survived; its writes then raced chown -R and aborted the update.

* Clean up comments in hermesagent.sh

Removed comments regarding hermes update and matching patterns.
2026-10-11 14:17:43 +02:00
community-scripts-pr-app[bot]
548e855118 Update CHANGELOG.md (#17853)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 12:03:34 +00:00
CanbiZ (MickLesk)
de19f51761 Radicale: install the bcrypt and argon2 extras (#17813)
* Radicale: install the bcrypt and argon2 extras

The update replaces pyproject.toml and the venv, so a bcrypt or argon2
module added by hand was gone afterwards and Radicale refused to start
with htpasswd_encryption = bcrypt, argon2 or autodetect. The service now
runs uv with --extra bcrypt --extra argon2, which upstream already
defines. The update patches existing units and restarts the service.

* Radicale: enable the extras only once the code defines them

argon2 is an extra since v3.5.4 and uv refuses unknown extras, so patching
before the release update broke older installs. Patch after it instead,
and only when pyproject.toml defines the extra.
2026-10-11 14:03:06 +02:00
community-scripts-pr-app[bot]
ad700e9691 Update CHANGELOG.md (#17851)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 11:24:54 +00:00
CanbiZ (MickLesk)
91bc5b3835 docker: take the lxcfs toggle, TCP socket and Compose choice from app variables (#17850)
* docker: take the lxcfs toggle, TCP socket and Compose choice from app variables

var_docker_lxcfs is exported for the core helper; var_docker_tcp_socket
(no/local/all) and var_docker_compose replace the prompts when set, so
the website generator can offer them. Alpine wrote daemon.json through
silent(), which captured the output and left the file empty.

* docker: use var_docker_socket, the name the catalog record already carries
2026-10-11 13:24:31 +02:00
community-scripts-pr-app[bot]
701268bff4 Update CHANGELOG.md (#17849)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 08:28:49 +00:00
community-scripts-pr-app[bot]
c1c7437ddc Update CHANGELOG.md (#17848)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 07:16:36 +00:00
community-scripts-pr-app[bot]
9c11f496c7 Update CHANGELOG.md (#17846)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 07:12:28 +00:00
community-scripts-pr-app[bot]
46196d179e Update CHANGELOG.md (#17844)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 06:50:36 +00:00
petermnt
3035f9216e fix(zigbee2mqtt): preserve backup stream and prevent filename collisions (#17751)
* fix(zigbee2mqtt): preserve backup tar stream in quiet mode

* fix(zigbee2mqtt): avoid backup collisions on repeated updates
2026-10-11 08:50:08 +02:00
community-scripts-pr-app[bot]
c80a171b36 Update CHANGELOG.md (#17840)
Some checks failed
Create Changelog Pull Request / update-changelog-pull-request (push) Has been cancelled
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 00:05:37 +00:00
community-scripts-pr-app[bot]
699228f646 Archive old changelog entries (#17839)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 00:05:12 +00:00
community-scripts-pr-app[bot]
31597fa698 Update CHANGELOG.md (#17838)
Some checks failed
Create Changelog Pull Request / update-changelog-pull-request (push) Has been cancelled
Set state to is_deleted in pocketbase / delete-pocketbase-entry (push) Has been cancelled
Sync ct/install to Incus / dispatch (push) Has been cancelled
Update script timestamp on .sh changes / update-script-timestamp (push) Has been cancelled
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-10 20:49:42 +00:00
push-app-to-main[bot]
0a8c97c765 Add weblate (ct) (#17837)
Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
2026-10-10 22:49:16 +02:00
community-scripts-pr-app[bot]
1bcd22137e Update CHANGELOG.md (#17834)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-10 14:30:13 +00:00
Johann Grobe
1bc4191951 update endurain repo from codeberg to gh (#17831)
* fix: endurain repo

* fix: endurain release check
2026-10-10 16:29:43 +02:00
community-scripts-pr-app[bot]
d1bad678e9 Update CHANGELOG.md (#17832)
Some checks failed
Create Changelog Pull Request / update-changelog-pull-request (push) Has been cancelled
Set state to is_deleted in pocketbase / delete-pocketbase-entry (push) Has been cancelled
Sync ct/install to Incus / dispatch (push) Has been cancelled
Update script timestamp on .sh changes / update-script-timestamp (push) Has been cancelled
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-10 10:28:07 +00:00
Clayton Faria
2d12d0e0b1 Immich: download countryInfo.txt into the geodata directory on update (#17823) 2026-10-10 12:27:40 +02:00
community-scripts-pr-app[bot]
cd06638952 Update CHANGELOG.md (#17829)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-10 07:11:43 +00:00
community-scripts-pr-app[bot]
65ee461b14 Update CHANGELOG.md (#17828)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-10 07:11:20 +00:00
push-app-to-main[bot]
9fdbb10a45 Add certmate (ct) (#17803)
Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
2026-10-10 09:11:09 +02:00
push-app-to-main[bot]
e274342a54 Add anythingllm (ct) (#17802)
Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
2026-10-10 09:10:51 +02:00
community-scripts-pr-app[bot]
05fd051fb6 Update CHANGELOG.md (#17826)
Some checks failed
Create Changelog Pull Request / update-changelog-pull-request (push) Has been cancelled
Set state to is_deleted in pocketbase / delete-pocketbase-entry (push) Has been cancelled
Sync ct/install to Incus / dispatch (push) Has been cancelled
Update script timestamp on .sh changes / update-script-timestamp (push) Has been cancelled
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-10 05:22:40 +00:00
Austin
c5c107c374 paperclip: honor custom PAPERCLIP_HOME on update (#17825)
The update path chowned a hardcoded /opt/paperclip-data and always moved
root-run services to a dedicated user. Installs that keep their data
elsewhere (for example an NFS bind mount reachable only by root) failed
with "chown: cannot access '/opt/paperclip-data'" after the rebuild, and a
non-root user could not have reached that data anyway.

Read PAPERCLIP_HOME from the install's .env. Keep the service as root when
it points somewhere other than /opt/paperclip-data, and only chown
/opt/paperclip-data when it is the configured data dir and exists.

Co-authored-by: root <root@paperclip.pilz.dev>
Co-authored-by: Claude <noreply@anthropic.com>
2026-10-10 07:22:13 +02:00
community-scripts-pr-app[bot]
8e11d877b9 Update CHANGELOG.md (#17818)
Some checks failed
Create Changelog Pull Request / update-changelog-pull-request (push) Has been cancelled
Set state to is_deleted in pocketbase / delete-pocketbase-entry (push) Has been cancelled
Sync ct/install to Incus / dispatch (push) Has been cancelled
Update script timestamp on .sh changes / update-script-timestamp (push) Has been cancelled
Stale PR Management / stale-prs (push) Has been cancelled
Lock closed issues / lock (push) Has been cancelled
Create Daily Release / create-daily-release (push) Has been cancelled
Delete merged branches / delete-merged-branches (push) Has been cancelled
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-09 19:27:09 +00:00
community-scripts-pr-app[bot]
623a7a1cf2 Update CHANGELOG.md (#17817)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-09 19:24:33 +00:00
CanbiZ (MickLesk)
969cc5e9b8 FileBrowser Quantum: migrate the config and database to v2 (#17815)
v2.0.0 reads the config strictly and stops at the v1 keys the addon
wrote (server.port, conditionals, indexingIntervalMinutes). It also only
imports the old BoltDB when server.database.migrateFrom names it and no
database.db is left in the working directory. The update now rewrites
the config, renames the database and points migrateFrom at it, keeping
a copy of the v1 config. New installs write the v2 layout.
2026-10-09 21:24:00 +02:00
community-scripts-pr-app[bot]
14cd4cb667 Update CHANGELOG.md (#17814)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-09 18:44:20 +00:00
Sim Kai Long
63cf41174f OpenCloud: allow OpenCloud to embed Collabora on 26.04.4 (#17810)
Collabora 26.04.4 ignores frame-ancestors set in content_security_policy,
so the editor iframe is blocked. Use net.frame_ancestors (as
opencloud-compose does) on install, and add it on update when missing.
2026-10-09 20:43:49 +02:00
community-scripts-pr-app[bot]
daa4daa927 Update CHANGELOG.md (#17807)
Some checks failed
Create Changelog Pull Request / update-changelog-pull-request (push) Has been cancelled
Set state to is_deleted in pocketbase / delete-pocketbase-entry (push) Has been cancelled
Sync ct/install to Incus / dispatch (push) Has been cancelled
Update script timestamp on .sh changes / update-script-timestamp (push) Has been cancelled
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-09 10:08:36 +00:00
CanbiZ (MickLesk)
227526cf55 Immich: survive an interrupted update and a failing ML build (#17798)
* Immich: survive an interrupted update and a failing ML build

An update cancelled midway leaves /opt/immich/app empty, and the next run
died at once on cd /opt/immich/app/bin to enable maintenance mode (#17796).
Maintenance mode is now only toggled when immich-admin exists.

uv sync fetching the ml-models git dependency failed with "Could not resolve
host" behind DNS filters such as AdGuard while DNS itself worked (#17797);
running uv one download at a time got through. Retries now do that.

If machine learning still cannot be built, the update no longer stops with
maintenance mode on and every service down: it finishes, starts the web
service, puts the previous version back into ~/.immich so the next update
retries, and exits with an error. Updates are also announced as taking
5-15 minutes, since the first report came from cancelling one that looked
stuck.

* Immich: point immich-ml at the moved ml_start.sh and clear failed units

The update moves ml_start.sh into app/machine-learning, but only rewrote
immich-web's ExecStart, so older containers kept starting ML from
/opt/immich/ml_start.sh and failed with 203/EXEC. Rewrite immich-ml the same
way. A crash loop before the update can also leave both units rate-limited,
which makes the final restart fail; reset them first.
2026-10-09 12:08:08 +02:00
community-scripts-pr-app[bot]
d271571ff7 Update CHANGELOG.md (#17806)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-09 06:32:19 +00:00
push-app-to-main[bot]
7100f6521c FoldingAtHome (#17799)
* Add foldingathome (ct)

* Clean up comments in foldingathome.sh

Removed comments about Git tags and installation process.

* Clean up comments in foldingathome-install.sh

Removed outdated comments regarding package installation and configuration.

---------

Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
Co-authored-by: CanbiZ (MickLesk) <47820557+MickLesk@users.noreply.github.com>
2026-10-09 08:31:48 +02:00
community-scripts-pr-app[bot]
387b8bf542 Update CHANGELOG.md (#17805)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-09 06:30:17 +00:00
push-app-to-main[bot]
a56510bf57 LocalAI (#17801)
* Add localai (ct)

* Refactor localai.sh to clean up comments and exports

Removed comments regarding ARM64 support and clarified install script export variables.

* Refactor variable assignments and clean up comments

Rearranged variable assignments and removed comments about SQLite and PostgreSQL.

---------

Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
Co-authored-by: CanbiZ (MickLesk) <47820557+MickLesk@users.noreply.github.com>
2026-10-09 08:29:50 +02:00
community-scripts-pr-app[bot]
05bc39e623 Update CHANGELOG.md (#17804)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-09 06:27:55 +00:00
push-app-to-main[bot]
6db1ebe154 Tvheadend (#17800)
* Add tvheadend (ct)

* Update Tvheadend installation messages in script

---------

Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
Co-authored-by: CanbiZ (MickLesk) <47820557+MickLesk@users.noreply.github.com>
2026-10-09 08:27:27 +02:00
69 changed files with 1565 additions and 393 deletions

187
.github/changelogs/2026/10.md generated vendored
View File

@@ -1,3 +1,190 @@
## 2026-10-10
### 🆕 New Scripts
- Weblate ([#17837](https://github.com/community-scripts/ProxmoxVE/pull/17837))
- CertMate ([#17803](https://github.com/community-scripts/ProxmoxVE/pull/17803))
- AnythingLLM ([#17802](https://github.com/community-scripts/ProxmoxVE/pull/17802))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- update endurain repo from codeberg to gh [@johanngrobe](https://github.com/johanngrobe) ([#17831](https://github.com/community-scripts/ProxmoxVE/pull/17831))
- Immich: download countryInfo.txt into the geodata directory on update [@claytonfaria](https://github.com/claytonfaria) ([#17823](https://github.com/community-scripts/ProxmoxVE/pull/17823))
- paperclip: keep root and skip /opt/paperclip-data chown when PAPERCLIP_HOME is custom [@austinpilz](https://github.com/austinpilz) ([#17825](https://github.com/community-scripts/ProxmoxVE/pull/17825))
## 2026-10-09
### 🆕 New Scripts
- FoldingAtHome ([#17799](https://github.com/community-scripts/ProxmoxVE/pull/17799))
- LocalAI ([#17801](https://github.com/community-scripts/ProxmoxVE/pull/17801))
- Tvheadend ([#17800](https://github.com/community-scripts/ProxmoxVE/pull/17800))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- OpenCloud: fix Collabora embedding with Collabora 26.04.4 [@SimKaiLong](https://github.com/SimKaiLong) ([#17810](https://github.com/community-scripts/ProxmoxVE/pull/17810))
- #### 🔧 Refactor
- Immich: survive an interrupted update and a failing ML build [@MickLesk](https://github.com/MickLesk) ([#17798](https://github.com/community-scripts/ProxmoxVE/pull/17798))
### 💾 Core
- check_for_release: compare against the release marked as latest [@MickLesk](https://github.com/MickLesk) ([core#125](https://github.com/community-scripts/core/pull/125))
### 🧰 Tools
- #### ✨ New Features
- FileBrowser Quantum: migrate the config and database to v2 [@MickLesk](https://github.com/MickLesk) ([#17815](https://github.com/community-scripts/ProxmoxVE/pull/17815))
## 2026-10-08
### 🆕 New Scripts
- Unifi-OS-Server VM ([#17752](https://github.com/community-scripts/ProxmoxVE/pull/17752))
- ZimaOS VM ([#17778](https://github.com/community-scripts/ProxmoxVE/pull/17778))
### 🚀 Updated Scripts
- Revert "Immich: Pin to v3.3.0" [@MickLesk](https://github.com/MickLesk) ([#17767](https://github.com/community-scripts/ProxmoxVE/pull/17767))
- #### 🐞 Bug Fixes
- Homarr: replace the musl better-sqlite3 that v2.3.0 ships for Debian [@MickLesk](https://github.com/MickLesk) ([#17789](https://github.com/community-scripts/ProxmoxVE/pull/17789))
- CLIProxyAPI: keep plugins and data across updates [@MickLesk](https://github.com/MickLesk) ([#17790](https://github.com/community-scripts/ProxmoxVE/pull/17790))
- Kima-Hub: install the Python services into a uv venv [@MickLesk](https://github.com/MickLesk) ([#17791](https://github.com/community-scripts/ProxmoxVE/pull/17791))
- #### ✨ New Features
- Immich: Pin to 3.3.0 / Update ML Python to 3.13 [@MickLesk](https://github.com/MickLesk) ([#17770](https://github.com/community-scripts/ProxmoxVE/pull/17770))
- #### 🔧 Refactor
- Refactor: OPNsense VM [@MickLesk](https://github.com/MickLesk) ([#17785](https://github.com/community-scripts/ProxmoxVE/pull/17785))
- Refactor: Nextcloud VM (Turnkey) [@MickLesk](https://github.com/MickLesk) ([#17787](https://github.com/community-scripts/ProxmoxVE/pull/17787))
- Refactor: OpenWrt VM [@MickLesk](https://github.com/MickLesk) ([#17774](https://github.com/community-scripts/ProxmoxVE/pull/17774))
- Refactor: Ubuntu VM [@MickLesk](https://github.com/MickLesk) ([#17776](https://github.com/community-scripts/ProxmoxVE/pull/17776))
### 💾 Core
- Tolerate a missing datacenter.cfg in vm_keyboard_default [@MickLesk](https://github.com/MickLesk) ([core#124](https://github.com/community-scripts/core/pull/124))
- Take the ISO storage from the disk pool when it can hold ISOs [@MickLesk](https://github.com/MickLesk) ([core#122](https://github.com/community-scripts/core/pull/122))
- Shared VM helpers: disk import, releases, checksums, first boot, IP by MAC [@MickLesk](https://github.com/MickLesk) ([core#117](https://github.com/community-scripts/core/pull/117))
- tools: forge truncated release list [@MickLesk](https://github.com/MickLesk) ([core#118](https://github.com/community-scripts/core/pull/118))
- Remember a kept cached image until the upstream changes [@MickLesk](https://github.com/MickLesk) ([core#119](https://github.com/community-scripts/core/pull/119))
- Choose the VM keyboard layout and carry the host's timezone into prepared images [@MickLesk](https://github.com/MickLesk) ([core#120](https://github.com/community-scripts/core/pull/120))
- VM's: run first-boot units without debconf dialogs [@MickLesk](https://github.com/MickLesk) ([core#121](https://github.com/community-scripts/core/pull/121))
## 2026-10-07
### 🆕 New Scripts
- Fedora VM ([#17747](https://github.com/community-scripts/ProxmoxVE/pull/17747))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- AudioMuse-AI: replace the venv on update without asking [@MickLesk](https://github.com/MickLesk) ([#17738](https://github.com/community-scripts/ProxmoxVE/pull/17738))
- paperclip: run as a dedicated non-root user so Claude Code can skip permissions [@samvandenbossche](https://github.com/samvandenbossche) ([#17707](https://github.com/community-scripts/ProxmoxVE/pull/17707))
- Thingsboard: update Java version from 17 to 25 [@CerberusStyle](https://github.com/CerberusStyle) ([#17733](https://github.com/community-scripts/ProxmoxVE/pull/17733))
- #### ✨ New Features
- Immich: Pin to v3.3.0 [@vhsdream](https://github.com/vhsdream) ([#17759](https://github.com/community-scripts/ProxmoxVE/pull/17759))
- #### 💥 Breaking Changes
- OpenCloud: bump to v8.1.0, rebuild search index on upgrade [@SimKaiLong](https://github.com/SimKaiLong) ([#17710](https://github.com/community-scripts/ProxmoxVE/pull/17710))
- #### 🔧 Refactor
- Pangolin: Unpin Release, stable enough, Bump to latest [@MickLesk](https://github.com/MickLesk) ([#17740](https://github.com/community-scripts/ProxmoxVE/pull/17740))
- Refactor: Archlinux-VM [@MickLesk](https://github.com/MickLesk) ([#17741](https://github.com/community-scripts/ProxmoxVE/pull/17741))
- Refactor: MikroTik RouterOS [@MickLesk](https://github.com/MickLesk) ([#17748](https://github.com/community-scripts/ProxmoxVE/pull/17748))
### 💾 Core
- Fix Fedora and BLS cloud image console setup [@MickLesk](https://github.com/MickLesk) ([core#116](https://github.com/community-scripts/core/pull/116))
- Keep setup_nodejs alive when the caller's directory is gone [@MickLesk](https://github.com/MickLesk) ([core#114](https://github.com/community-scripts/core/pull/114))
## 2026-10-06
### 🆕 New Scripts
- Pricebuddy ([#17708](https://github.com/community-scripts/ProxmoxVE/pull/17708))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- Webtrees: stop serving data/ and the source folders directly [@MickLesk](https://github.com/MickLesk) ([#17724](https://github.com/community-scripts/ProxmoxVE/pull/17724))
### 💾 Core
- Incus: check the architecture on Incus hosts too [@MickLesk](https://github.com/MickLesk) ([core#113](https://github.com/community-scripts/core/pull/113))
- Incus: Pass the app's var_* settings into Incus containers [@MickLesk](https://github.com/MickLesk) ([core#112](https://github.com/community-scripts/core/pull/112))
- Incus: stub storage_content_check on Incus [@MickLesk](https://github.com/MickLesk) ([core#104](https://github.com/community-scripts/core/pull/104))
- Incus: map Proxmox template versions to Incus image names [@MickLesk](https://github.com/MickLesk) ([core#111](https://github.com/community-scripts/core/pull/111))
- Incus: read storage names from .vars files [@MickLesk](https://github.com/MickLesk) ([core#110](https://github.com/community-scripts/core/pull/110))
- Incus: show the spinner inside containers again [@MickLesk](https://github.com/MickLesk) ([core#109](https://github.com/community-scripts/core/pull/109))
- Incus: set the hostname with sh, so it works before bash is installed [@MickLesk](https://github.com/MickLesk) ([core#102](https://github.com/community-scripts/core/pull/102))
- Incus: reserve a plain address on Incus, leave the gateway to the network [@MickLesk](https://github.com/MickLesk) ([core#101](https://github.com/community-scripts/core/pull/101))
- Incus: Wait for the network on Alpine OS too [@MickLesk](https://github.com/MickLesk) ([core#105](https://github.com/community-scripts/core/pull/105))
- Incus: do not fail the build when hostname -I is missing [@MickLesk](https://github.com/MickLesk) ([core#103](https://github.com/community-scripts/core/pull/103))
- Incus: Fuse always in unprivileged Containers, attach TUN only when container lacks it [@MickLesk](https://github.com/MickLesk) ([core#108](https://github.com/community-scripts/core/pull/108))
- Incus: accept mode=generated [@MickLesk](https://github.com/MickLesk) ([core#106](https://github.com/community-scripts/core/pull/106))
- Incus: pass the full install environment into Incus containers (quoted) [@MickLesk](https://github.com/MickLesk) ([core#107](https://github.com/community-scripts/core/pull/107))
## 2026-10-05
### 🚀 Updated Scripts
- Point to DevScripts, the renamed ProxmoxVED [@MickLesk](https://github.com/MickLesk) ([#17694](https://github.com/community-scripts/ProxmoxVE/pull/17694))
- #### 🐞 Bug Fixes
- wanderer: set the proxy secret and install plugins in their own directories [@MickLesk](https://github.com/MickLesk) ([#17698](https://github.com/community-scripts/ProxmoxVE/pull/17698))
- discourse: serve stylesheets and repair the update [@MickLesk](https://github.com/MickLesk) ([#17697](https://github.com/community-scripts/ProxmoxVE/pull/17697))
- wikijs: bump Node.js from 24 to 26 [@github-actions[bot]](https://github.com/github-actions[bot]) ([#17689](https://github.com/community-scripts/ProxmoxVE/pull/17689))
- jotty: bump Node.js from 22 to 24 [@github-actions[bot]](https://github.com/github-actions[bot]) ([#17688](https://github.com/community-scripts/ProxmoxVE/pull/17688))
### 💾 Core
- Read releases from github.com when the API is rate limited, resume stalled downloads [@MickLesk](https://github.com/MickLesk) ([core#99](https://github.com/community-scripts/core/pull/99))
- Check for template and container storage before the settings menu [@MickLesk](https://github.com/MickLesk) ([core#98](https://github.com/community-scripts/core/pull/98))
- Check /etc/pve before the settings menu [@MickLesk](https://github.com/MickLesk) ([core#97](https://github.com/community-scripts/core/pull/97))
- Check container settings before pct create rejects them [@MickLesk](https://github.com/MickLesk) ([core#96](https://github.com/community-scripts/core/pull/96))
- PVE: Smart Diagnosis - say why a container would not start [@MickLesk](https://github.com/MickLesk) ([core#95](https://github.com/community-scripts/core/pull/95))
- Retry template downloads that pveam reports as done but are not [@MickLesk](https://github.com/MickLesk) ([core#94](https://github.com/community-scripts/core/pull/94))
- Check the OS release against pve-container before creating anything [@MickLesk](https://github.com/MickLesk) ([core#93](https://github.com/community-scripts/core/pull/93))
- Rename "ProxmoxVED"-Links to "DevScripts" [@MickLesk](https://github.com/MickLesk) ([core#91](https://github.com/community-scripts/core/pull/91))
### 🧰 Tools
- #### 🐞 Bug Fixes
- monitor-all: read container IPs from the host side [@jasonobrien](https://github.com/jasonobrien) ([#17686](https://github.com/community-scripts/ProxmoxVE/pull/17686))
## 2026-10-04
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- immich: read the Intel runtime from the pinned release [@MickLesk](https://github.com/MickLesk) ([#17677](https://github.com/community-scripts/ProxmoxVE/pull/17677))
### 💾 Core
- better explain unsupported version & upgrade path for pve [@MickLesk](https://github.com/MickLesk) ([core#86](https://github.com/community-scripts/core/pull/86))
- Quote PostgreSQL identifiers and drop spaces from the creds file name [@MickLesk](https://github.com/MickLesk) ([core#89](https://github.com/community-scripts/core/pull/89))
- Find the default Rust toolchain in current rustup output [@MickLesk](https://github.com/MickLesk) ([core#88](https://github.com/community-scripts/core/pull/88))
## 2026-10-03
### 🆕 New Scripts

View File

@@ -113,6 +113,9 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
@@ -126,7 +129,7 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
<details>
<summary><h4>October (3 entries)</h4></summary>
<summary><h4>October (10 entries)</h4></summary>
[View October 2026 Changelog](.github/changelogs/2026/10.md)
@@ -559,6 +562,78 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
</details>
## 2026-10-11
### 🆕 New Scripts
- Cinephage ([#17852](https://github.com/community-scripts/ProxmoxVE/pull/17852))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- hermesagent: match the relaunched root gateway regardless of interpreter [@MickLesk](https://github.com/MickLesk) ([#17847](https://github.com/community-scripts/ProxmoxVE/pull/17847))
- Radicale: install the bcrypt and argon2 extras [@MickLesk](https://github.com/MickLesk) ([#17813](https://github.com/community-scripts/ProxmoxVE/pull/17813))
- fix(zigbee2mqtt): preserve backup stream and prevent filename collisions [@petermnt](https://github.com/petermnt) ([#17751](https://github.com/community-scripts/ProxmoxVE/pull/17751))
- #### ✨ New Features
- QoL: let var_* answer the optional add-on prompts [@MickLesk](https://github.com/MickLesk) ([#17858](https://github.com/community-scripts/ProxmoxVE/pull/17858))
- QoL: Confirm third-party installers through confirm_external_installer [@MickLesk](https://github.com/MickLesk) ([#17857](https://github.com/community-scripts/ProxmoxVE/pull/17857))
- docker: take the lxcfs toggle, TCP socket and Compose choice from app variables [@MickLesk](https://github.com/MickLesk) ([#17850](https://github.com/community-scripts/ProxmoxVE/pull/17850))
### 💾 Core
- Add confirm_external_installer [@MickLesk](https://github.com/MickLesk) ([core#130](https://github.com/community-scripts/core/pull/130))
- setup_docker: make LXC resource limits visible to nested containers [@andrebrait](https://github.com/andrebrait) ([core#9](https://github.com/community-scripts/core/pull/9))
- Incus: fix ENABLE_FUSE / TUN vars [@MickLesk](https://github.com/MickLesk) ([core#127](https://github.com/community-scripts/core/pull/127))
- Resolve a uv required-version range to the newest release inside it [@MickLesk](https://github.com/MickLesk) ([core#126](https://github.com/community-scripts/core/pull/126))
- Upgrade MongoDB in place when an app package depends on it [@MickLesk](https://github.com/MickLesk) ([core#128](https://github.com/community-scripts/core/pull/128))
## 2026-10-10
### 🆕 New Scripts
- Weblate ([#17837](https://github.com/community-scripts/ProxmoxVE/pull/17837))
- CertMate ([#17803](https://github.com/community-scripts/ProxmoxVE/pull/17803))
- AnythingLLM ([#17802](https://github.com/community-scripts/ProxmoxVE/pull/17802))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- update endurain repo from codeberg to gh [@johanngrobe](https://github.com/johanngrobe) ([#17831](https://github.com/community-scripts/ProxmoxVE/pull/17831))
- Immich: download countryInfo.txt into the geodata directory on update [@claytonfaria](https://github.com/claytonfaria) ([#17823](https://github.com/community-scripts/ProxmoxVE/pull/17823))
- paperclip: keep root and skip /opt/paperclip-data chown when PAPERCLIP_HOME is custom [@austinpilz](https://github.com/austinpilz) ([#17825](https://github.com/community-scripts/ProxmoxVE/pull/17825))
## 2026-10-09
### 🆕 New Scripts
- FoldingAtHome ([#17799](https://github.com/community-scripts/ProxmoxVE/pull/17799))
- LocalAI ([#17801](https://github.com/community-scripts/ProxmoxVE/pull/17801))
- Tvheadend ([#17800](https://github.com/community-scripts/ProxmoxVE/pull/17800))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- OpenCloud: fix Collabora embedding with Collabora 26.04.4 [@SimKaiLong](https://github.com/SimKaiLong) ([#17810](https://github.com/community-scripts/ProxmoxVE/pull/17810))
- #### 🔧 Refactor
- Immich: survive an interrupted update and a failing ML build [@MickLesk](https://github.com/MickLesk) ([#17798](https://github.com/community-scripts/ProxmoxVE/pull/17798))
### 💾 Core
- check_for_release: compare against the release marked as latest [@MickLesk](https://github.com/MickLesk) ([core#125](https://github.com/community-scripts/core/pull/125))
### 🧰 Tools
- #### ✨ New Features
- FileBrowser Quantum: migrate the config and database to v2 [@MickLesk](https://github.com/MickLesk) ([#17815](https://github.com/community-scripts/ProxmoxVE/pull/17815))
## 2026-10-08
### 🆕 New Scripts
@@ -1226,145 +1301,4 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
### 📚 Documentation
- issue template: add PVE release, execution context and phase; refresh distro list / pve versions [@MickLesk](https://github.com/MickLesk) ([#17160](https://github.com/community-scripts/ProxmoxVE/pull/17160))
## 2026-09-10
### 🆕 New Scripts
- Chevereto ([#17131](https://github.com/community-scripts/ProxmoxVE/pull/17131))
- Portabase ([#17111](https://github.com/community-scripts/ProxmoxVE/pull/17111))
- Logseq ([#17112](https://github.com/community-scripts/ProxmoxVE/pull/17112))
- Safebucket ([#17096](https://github.com/community-scripts/ProxmoxVE/pull/17096))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- Immich v3.2.0 [@vhsdream](https://github.com/vhsdream) ([#17137](https://github.com/community-scripts/ProxmoxVE/pull/17137))
- fix(solidtime): prevent composer install from hanging on root prompt [@supersoju](https://github.com/supersoju) ([#17146](https://github.com/community-scripts/ProxmoxVE/pull/17146))
- fix(hermesagent): wait for root gateway cleanup [@steveonjava](https://github.com/steveonjava) ([#17147](https://github.com/community-scripts/ProxmoxVE/pull/17147))
### 💾 Core
- Keep the script name when regenerating the entrypoint [@MickLesk](https://github.com/MickLesk) ([core#35](https://github.com/community-scripts/core/pull/35))
- Rewrite the dead Gitea base onto GitHub instead of failing the update [@MickLesk](https://github.com/MickLesk) ([core#33](https://github.com/community-scripts/core/pull/33))
- core.func: fall back to a usable HOME when the shell has none [@MickLesk](https://github.com/MickLesk) ([core#32](https://github.com/community-scripts/core/pull/32))
## 2026-09-09
### 🆕 New Scripts
- Lingarr ([#17130](https://github.com/community-scripts/ProxmoxVE/pull/17130))
### 🚀 Updated Scripts
- vm: drop the discussions link from the summary [@MickLesk](https://github.com/MickLesk) ([#17117](https://github.com/community-scripts/ProxmoxVE/pull/17117))
- #### 🐞 Bug Fixes
- fix(hermesagent): stop spurious root gateway after update [@steveonjava](https://github.com/steveonjava) ([#17126](https://github.com/community-scripts/ProxmoxVE/pull/17126))
## 2026-09-08
### 🆕 New Scripts
- Decypharr ([#17108](https://github.com/community-scripts/ProxmoxVE/pull/17108))
- Stash ([#17106](https://github.com/community-scripts/ProxmoxVE/pull/17106))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- Update Jellyfin FFmpeg dependency to version 8 [@MickLesk](https://github.com/MickLesk) ([#17109](https://github.com/community-scripts/ProxmoxVE/pull/17109))
### 💾 Core
- Treat a cut-short forge response as a failure, not as HTTP 200 [@MickLesk](https://github.com/MickLesk) ([core#31](https://github.com/community-scripts/core/pull/31))
- Generate app headers [@github-actions[bot]](https://github.com/github-actions[bot]) ([core#28](https://github.com/community-scripts/core/pull/28))
- cloud-init: drop the "configure in Proxmox UI" hint [@MickLesk](https://github.com/MickLesk) ([core#30](https://github.com/community-scripts/core/pull/30))
- Survive an empty /usr/bin/update instead of aborting the run [@MickLesk](https://github.com/MickLesk) ([core#29](https://github.com/community-scripts/core/pull/29))
## 2026-09-07
### 🆕 New Scripts
- Chatwoot ([#17095](https://github.com/community-scripts/ProxmoxVE/pull/17095))
- whisparr-eros ([#17094](https://github.com/community-scripts/ProxmoxVE/pull/17094))
- Matter-Hub ([#17093](https://github.com/community-scripts/ProxmoxVE/pull/17093))
- Journiv ([#17092](https://github.com/community-scripts/ProxmoxVE/pull/17092))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- kaneo: bump Node.js from 22 to 24 [@github-actions[bot]](https://github.com/github-actions[bot]) ([#17086](https://github.com/community-scripts/ProxmoxVE/pull/17086))
- iobroker: bump Node.js from 24 to 26 [@github-actions[bot]](https://github.com/github-actions[bot]) ([#17085](https://github.com/community-scripts/ProxmoxVE/pull/17085))
- reactive-resume: repair any wrong WorkingDirectory on update [@MickLesk](https://github.com/MickLesk) ([#17068](https://github.com/community-scripts/ProxmoxVE/pull/17068))
- mediamtx: keep mediamtx.yml across updates [@MickLesk](https://github.com/MickLesk) ([#17069](https://github.com/community-scripts/ProxmoxVE/pull/17069))
- omnitools: allow remote action while npm ci [@MickLesk](https://github.com/MickLesk) ([#17070](https://github.com/community-scripts/ProxmoxVE/pull/17070))
- #### ✨ New Features
- netboot-xyz: add Secure Boot and Legacy assets [@MickLesk](https://github.com/MickLesk) ([#17066](https://github.com/community-scripts/ProxmoxVE/pull/17066))
- #### 🔧 Refactor
- flatnotes: follow upstream move to uv and Python 3.13 [@MickLesk](https://github.com/MickLesk) ([#17090](https://github.com/community-scripts/ProxmoxVE/pull/17090))
- heimdall: set up PHP 8.4 on update, keep only the database, run migrations [@MickLesk](https://github.com/MickLesk) ([#17067](https://github.com/community-scripts/ProxmoxVE/pull/17067))
### 📂 Github
- github: Open per-script Node bump PRs [@MickLesk](https://github.com/MickLesk) ([#17065](https://github.com/community-scripts/ProxmoxVE/pull/17065))
## 2026-09-06
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- Fix Sonarqube update script to add +x on sonar.sh [@jarihu](https://github.com/jarihu) ([#17056](https://github.com/community-scripts/ProxmoxVE/pull/17056))
## 2026-09-05
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- authentik: scope blueprints chown to avoid recursing into the mp0 bind mount [@MickLesk](https://github.com/MickLesk) ([#17008](https://github.com/community-scripts/ProxmoxVE/pull/17008))
- iventoy: run iventoy.sh with bash instead of dash [@MickLesk](https://github.com/MickLesk) ([#17034](https://github.com/community-scripts/ProxmoxVE/pull/17034))
- frigate: restart go2rtc.service before frigate starts [@MickLesk](https://github.com/MickLesk) ([#17035](https://github.com/community-scripts/ProxmoxVE/pull/17035))
- snapotter: seed AI venv base packages on arm64, warn amd64 has no working CPU bundle [@MickLesk](https://github.com/MickLesk) ([#16903](https://github.com/community-scripts/ProxmoxVE/pull/16903))
- tolgee: bump required JDK from 21 to 25 [@MickLesk](https://github.com/MickLesk) ([#17005](https://github.com/community-scripts/ProxmoxVE/pull/17005))
- romm: write real version into backend/__version__.py placeholder [@MickLesk](https://github.com/MickLesk) ([#17009](https://github.com/community-scripts/ProxmoxVE/pull/17009))
- #### 🔧 Refactor
- Refactor FileFlows: Stop Spinner before read -rp / Switch from "Node" to "Agent" [@MickLesk](https://github.com/MickLesk) ([#17007](https://github.com/community-scripts/ProxmoxVE/pull/17007))
### 💾 Core
- update helper: follow renamed ct/ scripts instead of curling a 404 [@MickLesk](https://github.com/MickLesk) ([core#22](https://github.com/community-scripts/core/pull/22))
- Use Proxmox for a template before reaching for linuxcontainers.org [@MickLesk](https://github.com/MickLesk) ([core#23](https://github.com/community-scripts/core/pull/23))
- implement exponential backoff for curl retries in _cs_curl_retry function [@MickLesk](https://github.com/MickLesk) ([core#26](https://github.com/community-scripts/core/pull/26))
### 🧰 Tools
- #### 🐞 Bug Fixes
- update-apps: follow renamed ct/ scripts instead of erroring out [@MickLesk](https://github.com/MickLesk) ([#16991](https://github.com/community-scripts/ProxmoxVE/pull/16991))
## 2026-09-04
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- fix(shlink): preserve servers.json across web-client updates [@Corgei](https://github.com/Corgei) ([#17023](https://github.com/community-scripts/ProxmoxVE/pull/17023))
- fix-update-authentik-2026.8.1 [@thieneret](https://github.com/thieneret) ([#16999](https://github.com/community-scripts/ProxmoxVE/pull/16999))
- Fix npm v12 allow-git/allow-remote restrictions across affected scripts [@MickLesk](https://github.com/MickLesk) ([#17014](https://github.com/community-scripts/ProxmoxVE/pull/17014))
- Fix/poznote - 1st party Docker parity [@lucas-at-3x-eye](https://github.com/lucas-at-3x-eye) ([#17011](https://github.com/community-scripts/ProxmoxVE/pull/17011))
### 💾 Core
- setup_go: resolve bare major.minor versions to the latest patch release [@MickLesk](https://github.com/MickLesk) ([core#24](https://github.com/community-scripts/core/pull/24))
- issue template: add PVE release, execution context and phase; refresh distro list / pve versions [@MickLesk](https://github.com/MickLesk) ([#17160](https://github.com/community-scripts/ProxmoxVE/pull/17160))

78
ct/anythingllm.sh Normal file
View File

@@ -0,0 +1,78 @@
#!/usr/bin/env bash
# Engine comes from community-scripts/core; this repo only ships the scripts.
# A local core checkout wins (COMMUNITY_SCRIPTS_CORE_DIR, else a sibling ../core),
# so a fork or branch of core can be tested without editing this file.
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/Mintplex-Labs/anything-llm
APP="AnythingLLM"
var_tags="${var_tags:-ai;rag}"
var_cpu="${var_cpu:-4}"
var_ram="${var_ram:-6144}"
var_disk="${var_disk:-20}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_gpu="${var_gpu:-yes}"
#var_arm64="${var_arm64:-no}" # unset = ask the user; set yes/no only when verified
var_unprivileged="${var_unprivileged:-1}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -d /opt/anythingllm ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "anythingllm" "Mintplex-Labs/anything-llm"; then
msg_info "Stopping Services"
systemctl stop anythingllm anythingllm-collector
msg_ok "Stopped Services"
create_backup /opt/anythingllm/server/.env /opt/anythingllm/collector/.env /opt/anythingllm/frontend/.env
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "anythingllm" "Mintplex-Labs/anything-llm" "tarball"
restore_backup
msg_info "Building AnythingLLM (Patience)"
cd /opt/anythingllm
export PUPPETEER_SKIP_DOWNLOAD=true
export NODE_OPTIONS="--max-old-space-size=3072"
$STD yarn setup
cd /opt/anythingllm/frontend
$STD yarn build
rm -rf /opt/anythingllm/server/public
cp -R /opt/anythingllm/frontend/dist /opt/anythingllm/server/public
cd /opt/anythingllm/server
$STD npx prisma generate --schema=./prisma/schema.prisma
$STD npx prisma migrate deploy --schema=./prisma/schema.prisma
msg_ok "Built AnythingLLM"
msg_info "Starting Services"
systemctl start anythingllm anythingllm-collector
msg_ok "Started Services"
msg_ok "Updated successfully!"
fi
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}:3001${CL}"

65
ct/certmate.sh Normal file
View File

@@ -0,0 +1,65 @@
#!/usr/bin/env bash
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: fabriziosalmi
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/fabriziosalmi/certmate
APP="CertMate"
var_tags="${var_tags:-ssl;certificates;acme}"
var_cpu="${var_cpu:-2}"
var_ram="${var_ram:-2048}"
var_disk="${var_disk:-8}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
#var_arm64="${var_arm64:-no}" # unset = ask the user; set yes/no only when verified
var_unprivileged="${var_unprivileged:-1}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -d /opt/certmate ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "certmate" "fabriziosalmi/certmate"; then
msg_info "Stopping CertMate"
systemctl stop certmate
msg_ok "Stopped CertMate"
PYTHON_VERSION="3.12" setup_uv
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "certmate" "fabriziosalmi/certmate" "tarball"
msg_info "Installing CertMate Dependencies"
cd /opt/certmate
$STD uv venv --python 3.12 /opt/certmate/.venv
$STD uv pip sync --python /opt/certmate/.venv/bin/python requirements.lock
$STD /opt/certmate/.venv/bin/certbot --version
msg_ok "Installed CertMate Dependencies"
msg_info "Starting CertMate"
systemctl start certmate
msg_ok "Started CertMate"
msg_ok "Updated successfully!"
fi
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}:8000${CL}"
echo -e "${INFO}${YW}The first page creates the admin account and asks for the API token: grep API_BEARER_TOKEN /opt/certmate_data/.env${CL}"

69
ct/cinephage.sh Normal file
View File

@@ -0,0 +1,69 @@
#!/usr/bin/env bash
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/MoldyTaint/Cinephage
APP="Cinephage"
var_tags="${var_tags:-arr;media;torrent;usenet}"
var_cpu="${var_cpu:-2}"
var_ram="${var_ram:-4096}"
var_disk="${var_disk:-10}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-yes}"
var_unprivileged="${var_unprivileged:-1}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -d /opt/cinephage ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "cinephage" "MoldyTaint/Cinephage"; then
msg_info "Stopping Cinephage"
systemctl stop cinephage
msg_ok "Stopped Cinephage"
NODE_VERSION="24" setup_nodejs
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "cinephage" "MoldyTaint/Cinephage" "tarball"
msg_info "Building Cinephage"
cd /opt/cinephage
$STD npm ci
$STD npm run build
$STD npm prune --omit=dev
sed -i "s/^APP_VERSION=.*/APP_VERSION=$(cat ~/.cinephage)/" /opt/cinephage_data/.env
msg_ok "Built Cinephage"
msg_info "Updating Camoufox"
$STD /opt/cinephage/node_modules/.bin/camoufox-js fetch
msg_ok "Updated Camoufox"
msg_info "Starting Cinephage"
systemctl start cinephage
msg_ok "Started Cinephage"
msg_ok "Updated successfully!"
fi
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}:3000${CL}"

View File

@@ -27,6 +27,10 @@ else
var_disk="${var_disk:-4}"
var_version="${var_version:-13}"
fi
# Only exported variables reach the install through lxc-attach.
export var_docker_socket="${var_docker_socket:-}"
export var_docker_compose="${var_docker_compose:-}"
export var_docker_lxcfs="${var_docker_lxcfs:-}"
header_info "$APP"
variables

View File

@@ -30,14 +30,14 @@ function update_script() {
msg_error "No ${APP} installation found!"
exit 233
fi
if check_for_codeberg_release "endurain" "endurain-project/endurain"; then
if check_for_gh_release "endurain" "endurain-project/endurain"; then
msg_info "Stopping Service"
systemctl stop endurain
msg_ok "Stopped Service"
NODE_VERSION="24" setup_nodejs
create_backup /opt/endurain/.env /opt/endurain/frontend/dist/env.js
CLEAN_INSTALL=1 fetch_and_deploy_codeberg_release "endurain" "endurain-project/endurain" "tarball" "latest" "/opt/endurain"
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "endurain" "endurain-project/endurain"
msg_info "Updating Endurain Frontend"
cd /opt/endurain

52
ct/foldingathome.sh Normal file
View File

@@ -0,0 +1,52 @@
#!/usr/bin/env bash
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ) | Co-Author: 007hacky007
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/FoldingAtHome/fah-client-bastet
APP="FoldingAtHome"
var_tags="${var_tags:-science;distributed-computing}"
var_cpu="${var_cpu:-4}"
var_ram="${var_ram:-2048}"
var_disk="${var_disk:-8}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-yes}"
var_gpu="${var_gpu:-yes}"
var_unprivileged="${var_unprivileged:-1}"
export var_fah_token="${var_fah_token:-}"
export var_fah_machine_name="${var_fah_machine_name:-}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -f /usr/bin/fah-client ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
fetch_and_deploy_from_url "https://download.foldingathome.org/releases/public/fah-client/$(arch_resolve "debian-10-64bit" "debian-stable-arm64")/release/latest.deb"
msg_ok "Folding@home is at $(dpkg-query -W -f='${Version}' fah-client)"
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Manage it from the Folding@home Web Control:${CL}"
echo -e "${GATEWAY}${BGN}https://app.foldingathome.org/${CL}"
echo -e "${INFO}${YW}The client starts paused - press Fold once the machine shows up in your account${CL}"
echo -e "${INFO}${YW}Account token and machine name are in /etc/fah-client/config.xml${CL}"

View File

@@ -31,16 +31,7 @@ function update_script() {
exit
fi
msg_warn "WARNING: This script will run an external installer from a third-party source (https://hermes-agent.nousresearch.com/)."
msg_warn "The following code is NOT maintained or audited by our repository."
msg_warn "If you have any doubts or concerns, please review the installer code before proceeding:"
msg_custom "${TAB3}${GATEWAY}${BGN}${CL}" "\e[1;34m" "→ hermes update (https://hermes-agent.nousresearch.com/)"
echo
read -r -p "${TAB3}Do you want to continue? [y/N]: " CONFIRM
if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
msg_error "Aborted by user. No changes have been made."
exit 10
fi
confirm_external_installer "https://hermes-agent.nousresearch.com/" "hermes update (https://hermes-agent.nousresearch.com/)"
msg_info "Stopping Services"
systemctl stop hermes-dashboard
@@ -51,8 +42,7 @@ function update_script() {
set -a; source /etc/default/hermes; set +a
/home/hermes/.local/bin/hermes update --yes
'
# See https://github.com/community-scripts/ProxmoxVE/issues/17123
mapfile -t root_gateway_pids < <(ps -eo user=,pid=,args= | awk '$1 == "root" && $0 ~ /\/home\/hermes\/\.hermes\/hermes-agent\/venv\/bin\/python -m hermes_cli\.main gateway run --replace$/ { print $2 }')
mapfile -t root_gateway_pids < <(ps -eo user=,pid=,args= | awk '$1 == "root" && /\/home\/hermes\/\.hermes\// && /hermes_cli[.]main/ && / gateway run --replace$/ { print $2 }')
if ((${#root_gateway_pids[@]})); then
kill -TERM "${root_gateway_pids[@]}"
for pid in "${root_gateway_pids[@]}"; do
@@ -61,7 +51,14 @@ function update_script() {
done
done
fi
chown -R hermes:hermes /home/hermes
if ps -eo user=,args= | awk '$1 == "root" && /\/home\/hermes\/\.hermes\// { found = 1 } END { exit !found }'; then
msg_warn "A root-owned Hermes process is still running; it may keep writing root-owned files"
fi
# A writer racing chown makes files vanish between readdir and chown; one retry covers it.
if ! chown -R hermes:hermes /home/hermes 2>/dev/null; then
sleep 1
chown -R hermes:hermes /home/hermes || msg_warn "Could not take ownership of everything under /home/hermes"
fi
msg_ok "Updated Hermes Agent"
msg_info "Starting Services"

View File

@@ -106,7 +106,7 @@ EOF
libraries=("libjxl" "jpegli" "libheif" "libraw" "imagemagick" "libvips")
cd "$BASE_DIR"
msg_warn "Checking for updates to custom image-processing libraries (recompile time: 2-15min per library)"
ensure_dependencies liblcms2-dev libjpeg62-turbo-dev libspng-dev libexif-dev
ensure_dependencies liblcms2-dev libjpeg62-turbo-dev libspng-dev libexif-dev libopenjp2-7-dev
$STD git pull
for library in "${libraries[@]}"; do
compile_"$library"
@@ -115,7 +115,10 @@ EOF
fi
if check_for_gh_release "Immich" "immich-app/immich" "${RELEASE}" "each release is tested individually before the version is updated. Please do not open issues for this"; then
if [[ $(cat ~/.immich) > "2.5.1" ]]; then
msg_warn "The update takes 5-15 minutes, do not interrupt it"
PREV_IMMICH="$(cat ~/.immich)"
# An interrupted update leaves app/ empty, so there may be no immich-admin to call.
if [[ "$PREV_IMMICH" > "2.5.1" && -x /opt/immich/app/bin/immich-admin ]]; then
msg_info "Enabling Maintenance Mode"
cd /opt/immich/app/bin
$STD ./immich-admin enable-maintenance-mode || true
@@ -273,12 +276,14 @@ EOF
msg_ok "Pre-installed Python ${ML_PYTHON}"
msg_info "Updating Intel OpenVINO machine-learning"
for attempt in $(seq 1 3); do
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT -Pnu immich uv sync --extra openvino --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
[[ $attempt -eq 3 ]] && { msg_error "uv sync failed three times, the machine-learning environment was not built"; exit 1; }
msg_warn "uv sync attempt $attempt failed, retrying..." && sleep 10
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT,UV_CONCURRENT_DOWNLOADS,UV_CONCURRENT_BUILDS,UV_CONCURRENT_INSTALLS -Pnu immich uv sync --extra openvino --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
[[ $attempt -eq 3 ]] && { ML_FAILED=1; break; }
# Parallel fetches can trip DNS rate limits (AdGuard, Pi-hole); retry one at a time.
export UV_CONCURRENT_DOWNLOADS=1 UV_CONCURRENT_BUILDS=1 UV_CONCURRENT_INSTALLS=1
msg_warn "uv sync attempt $attempt failed, retrying one download at a time..." && sleep 10
done
patchelf --clear-execstack "${VIRTUAL_ENV}/lib/python3.13/site-packages/onnxruntime/capi/onnxruntime_pybind11_state.cpython-313-$(arch_resolve "x86_64" "aarch64")-linux-gnu.so"
msg_ok "Updated Intel OpenVINO machine-learning"
[[ "${ML_FAILED:-0}" == 1 ]] || patchelf --clear-execstack "${VIRTUAL_ENV}/lib/python3.13/site-packages/onnxruntime/capi/onnxruntime_pybind11_state.cpython-313-$(arch_resolve "x86_64" "aarch64")-linux-gnu.so"
[[ "${ML_FAILED:-0}" == 1 ]] || msg_ok "Updated Intel OpenVINO machine-learning"
else
ML_PYTHON="python3.13"
msg_info "Pre-installing Python ${ML_PYTHON} for machine-learning"
@@ -289,12 +294,15 @@ EOF
msg_ok "Pre-installed Python ${ML_PYTHON}"
msg_info "Updating machine-learning"
for attempt in $(seq 1 3); do
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT -Pnu immich uv sync --extra cpu --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
[[ $attempt -eq 3 ]] && { msg_error "uv sync failed three times, the machine-learning environment was not built"; exit 1; }
msg_warn "uv sync attempt $attempt failed, retrying..." && sleep 10
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT,UV_CONCURRENT_DOWNLOADS,UV_CONCURRENT_BUILDS,UV_CONCURRENT_INSTALLS -Pnu immich uv sync --extra cpu --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
[[ $attempt -eq 3 ]] && { ML_FAILED=1; break; }
# Parallel fetches can trip DNS rate limits (AdGuard, Pi-hole); retry one at a time.
export UV_CONCURRENT_DOWNLOADS=1 UV_CONCURRENT_BUILDS=1 UV_CONCURRENT_INSTALLS=1
msg_warn "uv sync attempt $attempt failed, retrying one download at a time..." && sleep 10
done
msg_ok "Updated machine-learning"
[[ "${ML_FAILED:-0}" == 1 ]] || msg_ok "Updated machine-learning"
fi
[[ "${ML_FAILED:-0}" == 1 ]] && msg_warn "uv sync failed three times, machine learning was not updated"
cd "$SRC_DIR"
cp -a machine-learning/{ann,immich_ml} "$ML_DIR"
[[ -f "$INSTALL_DIR"/ml_start.sh ]] && mv "$INSTALL_DIR"/ml_start.sh "$ML_DIR"
@@ -321,7 +329,7 @@ EOF
grep -rl /usr/src | xargs -n1 sed -i "s|\/usr/src|$INSTALL_DIR|g"
grep -rlE "'/build'" | xargs -n1 sed -i "s|'/build'|'$APP_DIR'|g"
sed -i "s@\"/cache\"@\"$INSTALL_DIR/cache\"@g" "$ML_DIR"/immich_ml/config.py
[[ ! -f "$GEO_DIR/countryInfo.txt" ]] && curl_with_retry "https://download.geonames.org/export/dump/countryInfo.txt" "countryInfo.txt"
[[ ! -f "$GEO_DIR/countryInfo.txt" ]] && curl_with_retry "https://download.geonames.org/export/dump/countryInfo.txt" "$GEO_DIR/countryInfo.txt"
ln -s "${UPLOAD_DIR:-/opt/immich/upload}" "$APP_DIR"/upload
ln -s "${UPLOAD_DIR:-/opt/immich/upload}" "$ML_DIR"/upload
ln -sfn "$GEO_DIR" "$APP_DIR/geodata"
@@ -345,6 +353,10 @@ EOF
sed -i "s|^ExecStart=.*|ExecStart=${APP_DIR}/bin/start.sh|" /etc/systemd/system/immich-web.service
systemctl daemon-reload
fi
if grep -q "^ExecStart=${INSTALL_DIR}/ml_start.sh" /etc/systemd/system/immich-ml.service; then
sed -i "s|^ExecStart=.*|ExecStart=${ML_DIR}/ml_start.sh|" /etc/systemd/system/immich-ml.service
systemctl daemon-reload
fi
# MickLesk temporary patch for HEIC thumbnail gen
MEDIA_REPO_JS="/opt/immich/app/dist/repositories/media.repository.js"
@@ -366,6 +378,15 @@ EOF
$STD cd -
msg_ok "Disabled Maintenance Mode"
fi
# A crash loop before the update leaves the units rate-limited, and restart would refuse.
systemctl reset-failed immich-ml immich-web 2>/dev/null || true
if [[ "${ML_FAILED:-0}" == 1 ]]; then
systemctl restart immich-web || true
[[ -f /etc/systemd/system/immich-proxy.service ]] && systemctl restart immich-proxy
echo "$PREV_IMMICH" >~/.immich
msg_error "Immich runs, but without machine learning (see the uv output above). Run update again to retry."
exit 1
fi
systemctl restart immich-ml immich-web
[[ -f /etc/systemd/system/immich-proxy.service ]] && systemctl restart immich-proxy
msg_ok "Updated successfully!"
@@ -544,7 +565,9 @@ function compile_imagemagick() {
function compile_libvips() {
SOURCE=$SOURCE_DIR/libvips
LIBVIPS_REVISION="$(jq -cr '.revision' "$BASE_DIR"/server/sources/libvips.json)"
if [[ "$LIBVIPS_REVISION" != "$(grep 'libvips' ~/.immich_library_revisions | awk '{print $2}')" ]]; then
# Builds made before libopenjp2-7-dev was installed lack JPEG 2000
if [[ "$LIBVIPS_REVISION" != "$(grep 'libvips' ~/.immich_library_revisions | awk '{print $2}')" ]] ||
[[ "$(vips -l foreign 2>/dev/null)" != *jp2kload* ]]; then
msg_info "Recompiling libvips"
[[ -d "$SOURCE" ]] && rm -rf "$SOURCE"
$STD git clone https://github.com/libvips/libvips.git "$SOURCE"

View File

@@ -62,16 +62,7 @@ function update_script() {
msg_info "Updating Kasm"
cd /tmp
msg_warn "WARNING: This script will run an external installer from a third-party source (https://www.kasmweb.com/)."
msg_warn "The following code is NOT maintained or audited by our repository."
msg_warn "If you have any doubts or concerns, please review the installer code before proceeding:"
msg_custom "${TAB3}${GATEWAY}${BGN}${CL}" "\e[1;34m" "→ upgrade.sh inside tar.gz $KASM_URL"
echo
read -r -p "${TAB3}Do you want to continue? [y/N]: " CONFIRM
if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
msg_error "Aborted by user. No changes have been made."
exit 10
fi
confirm_external_installer "https://www.kasmweb.com/" "upgrade.sh inside tar.gz $KASM_URL"
curl_download "/tmp/kasm_release_${KASM_VERSION}.tar.gz" "$KASM_URL"
tar -xf "kasm_release_${KASM_VERSION}.tar.gz"
chmod +x /tmp/kasm_release/install.sh

63
ct/localai.sh Normal file
View File

@@ -0,0 +1,63 @@
#!/usr/bin/env bash
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: Bryan Lieberman (BryanCLieberman)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://localai.io
APP="LocalAI"
var_tags="${var_tags:-ai;llm;api}"
var_cpu="${var_cpu:-4}"
var_ram="${var_ram:-8192}"
var_disk="${var_disk:-30}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-yes}"
var_gpu="${var_gpu:-yes}"
var_unprivileged="${var_unprivileged:-1}"
# Values the install script accepts up front
export var_auth="${var_auth:-no}"
export var_api_key="${var_api_key:-}"
export var_port="${var_port:-8080}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -d /opt/localai ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "localai" "mudler/LocalAI"; then
msg_info "Stopping Service"
systemctl stop localai
msg_ok "Stopped Service"
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "localai" "mudler/LocalAI" "singlefile" "latest" "/opt/localai" "local-ai-v*-linux-$(arch_resolve amd64 arm64)"
msg_info "Starting Service"
systemctl start localai
msg_ok "Started Service"
msg_ok "Updated successfully!"
fi
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}:8080${CL}"
echo -e "${INFO}${YW}Install models from the gallery in the web UI or place GGUF files in /opt/localai_data/models${CL}"

View File

@@ -31,6 +31,15 @@ function update_script() {
exit
fi
# Collabora 26.04.4 ignores frame-ancestors in content_security_policy; outside the release
# check so installs already on the current release get it too
if [[ -f /etc/coolwsd/coolwsd.xml ]] && ! grep -q '<frame_ancestors[^>]*>[^<[:space:]]' /etc/coolwsd/coolwsd.xml; then
msg_info "Allowing OpenCloud to embed Collabora"
$STD sudo -u cool coolconfig set net.frame_ancestors "$(sed -n 's/^OC_URL=//p' /etc/opencloud/opencloud.env)"
systemctl restart coolwsd
msg_ok "Allowed OpenCloud to embed Collabora"
fi
RELEASE="v8.1.0"
if check_for_gh_release "OpenCloud" "opencloud-eu/opencloud" "${RELEASE}" "each release is tested individually before the version is updated. Please do not open issues for this"; then
OLD_VERSION="$(cat ~/.opencloud 2>/dev/null)"

View File

@@ -63,7 +63,13 @@ function update_script() {
# Claude Code refuses --dangerously-skip-permissions as root; migrate existing installs to a dedicated user
PAPERCLIP_USER=$(sed -n 's/^User=//p' /etc/systemd/system/paperclip.service)
if [[ -z "$PAPERCLIP_USER" || "$PAPERCLIP_USER" == "root" ]]; then
PAPERCLIP_HOME=$(sed -n 's/^PAPERCLIP_HOME=//p' /opt/paperclip-ai/.env)
PAPERCLIP_HOME="${PAPERCLIP_HOME:-/opt/paperclip-data}"
if [[ -z "$PAPERCLIP_USER" || "$PAPERCLIP_USER" == "root" ]] && [[ "$PAPERCLIP_HOME" != "/opt/paperclip-data" ]]; then
# A custom data dir (e.g. an NFS bind mount) may only be reachable by root; don't move the service off root
msg_warn "PAPERCLIP_HOME is ${PAPERCLIP_HOME}; keeping the service user as root"
PAPERCLIP_USER=root
elif [[ -z "$PAPERCLIP_USER" || "$PAPERCLIP_USER" == "root" ]]; then
PAPERCLIP_USER="${var_paperclip_user:-paperclip}"
if [[ "$PAPERCLIP_USER" == "root" || ! "$PAPERCLIP_USER" =~ ^[a-z_][a-z0-9_-]{0,31}$ ]]; then
msg_error "Invalid var_paperclip_user '${PAPERCLIP_USER}' (must be a non-root lowercase Linux username)"
@@ -85,7 +91,10 @@ function update_script() {
fi
PAPERCLIP_USER_HOME=$(getent passwd "$PAPERCLIP_USER" | cut -d: -f6)
chmod 600 /opt/paperclip-ai/.env
chown -R "${PAPERCLIP_USER}:${PAPERCLIP_USER}" /opt/paperclip-ai /opt/paperclip-data "$PAPERCLIP_USER_HOME"
chown -R "${PAPERCLIP_USER}:${PAPERCLIP_USER}" /opt/paperclip-ai "$PAPERCLIP_USER_HOME"
if [[ "$PAPERCLIP_HOME" == "/opt/paperclip-data" && -d /opt/paperclip-data ]]; then
chown -R "${PAPERCLIP_USER}:${PAPERCLIP_USER}" /opt/paperclip-data
fi
msg_info "Running Database Migrations"
set -a && source /opt/paperclip-ai/.env && set +a

View File

@@ -41,7 +41,7 @@ function update_script() {
if grep -q 'start.sh' /etc/systemd/system/radicale.service; then
sed -i -e '/^Description/i[Unit]' \
-e '\|^ExecStart|iWorkingDirectory=/opt/radicale' \
-e 's|^ExecStart=.*|ExecStart=/usr/local/bin/uv run -m radicale --config /etc/radicale/config|' /etc/systemd/system/radicale.service
-e 's|^ExecStart=.*|ExecStart=/usr/local/bin/uv run --extra bcrypt --extra argon2 -m radicale --config /etc/radicale/config|' /etc/systemd/system/radicale.service
systemctl daemon-reload
fi
if [[ ! -f /etc/radicale/config ]]; then
@@ -70,6 +70,14 @@ EOF
msg_ok "Started service"
msg_ok "Updated Successfully!"
fi
if grep -q 'uv run -m radicale' /etc/systemd/system/radicale.service && grep -q '^argon2 *=' /opt/radicale/pyproject.toml; then
msg_info "Enabling bcrypt/argon2 support"
sed -i 's|uv run -m radicale|uv run --extra bcrypt --extra argon2 -m radicale|' /etc/systemd/system/radicale.service
systemctl daemon-reload
systemctl restart radicale
msg_ok "Enabled bcrypt/argon2 support"
fi
exit
}

58
ct/tvheadend.sh Normal file
View File

@@ -0,0 +1,58 @@
#!/usr/bin/env bash
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: Nicolas Pastorello (opastorello)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://tvheadend.org/ | Github: https://github.com/tvheadend/tvheadend
APP="Tvheadend"
var_tags="${var_tags:-media;pvr;tv;dvr}"
var_cpu="${var_cpu:-2}"
var_ram="${var_ram:-2048}"
var_disk="${var_disk:-8}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
#var_arm64="${var_arm64:-no}" # unset = ask the user; set yes/no only when verified
var_unprivileged="${var_unprivileged:-1}"
export var_admin_user="${var_admin_user:-admin}"
export var_admin_pass="${var_admin_pass:-$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | cut -c1-13)}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -d /var/lib/tvheadend ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
msg_info "Updating Tvheadend"
$STD apt update
$STD apt install -y tvheadend
msg_ok "Updated Tvheadend"
msg_info "Restarting Service"
systemctl restart tvheadend
msg_ok "Restarted Service"
msg_ok "Updated successfully!"
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}:9981${CL}"
echo -e "${INFO}${YW}Admin Username: ${var_admin_user}${CL}"
echo -e "${INFO}${YW}Admin Password: ${var_admin_pass}${CL}"

67
ct/weblate.sh Normal file
View File

@@ -0,0 +1,67 @@
#!/usr/bin/env bash
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/WeblateOrg/weblate
APP="Weblate"
var_tags="${var_tags:-translation;localization}"
var_cpu="${var_cpu:-2}"
var_ram="${var_ram:-3072}"
var_disk="${var_disk:-10}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-yes}"
var_unprivileged="${var_unprivileged:-1}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -d /opt/weblate ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "weblate" "WeblateOrg/weblate"; then
msg_info "Stopping Weblate"
systemctl stop weblate weblate-celery
msg_ok "Stopped Weblate"
PYTHON_VERSION="3.14" setup_uv
USE_ORIGINAL_FILENAME=true fetch_and_deploy_gh_release "weblate" "WeblateOrg/weblate" "singlefile" "latest" "/opt/weblate" "weblate-*-py3-none-any.whl"
msg_info "Updating Weblate"
$STD uv pip install --python /opt/weblate/.venv/bin/python --compile-bytecode /opt/weblate/weblate-*.whl "weblate[all,wsgi]"
rm -f /opt/weblate/weblate-*.whl
set -a
source /opt/weblate_data/weblate.env
set +a
$STD /opt/weblate/.venv/bin/weblate migrate --noinput
$STD /opt/weblate/.venv/bin/weblate collectstatic --noinput
msg_ok "Updated Weblate"
msg_info "Starting Weblate"
systemctl start weblate-celery weblate
msg_ok "Started Weblate"
msg_ok "Updated successfully!"
fi
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}${CL}"

View File

@@ -49,8 +49,12 @@ update_deb_based() {
ensure_dependencies zstd
mkdir -p /opt/backups
BACKUP_VERSION="$(<"$HOME/.zigbee2mqtt")"
BACKUP_FILE="/opt/backups/${APP}_backup_${BACKUP_VERSION}.tar.zst"
$STD tar -cf - -C /opt zigbee2mqtt | zstd -q -o "$BACKUP_FILE"
BACKUP_FILE="$(mktemp "/opt/backups/${APP}_backup_${BACKUP_VERSION}_XXXXXX.tar.zst")"
tar -cf - -C /opt zigbee2mqtt | $STD zstd -q -f -o "$BACKUP_FILE" || {
local backup_exit_code=$?
rm -f "$BACKUP_FILE"
return "$backup_exit_code"
}
ls -t /opt/backups/${APP}_backup_*.tar.zst 2>/dev/null | tail -n +6 | xargs -r rm -f
msg_ok "Backup Created (${BACKUP_VERSION})"

View File

@@ -0,0 +1,107 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/Mintplex-Labs/anything-llm
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
msg_info "Installing Dependencies"
$STD apt install -y \
build-essential \
python3-dev \
libgomp1 \
git \
chromium
msg_ok "Installed Dependencies"
NODE_VERSION="22" NODE_MODULE="yarn" setup_nodejs
fetch_and_deploy_gh_release "anythingllm" "Mintplex-Labs/anything-llm" "tarball"
msg_info "Configuring AnythingLLM"
mkdir -p /opt/anythingllm_data/storage
cp -RTn /opt/anythingllm/server/storage /opt/anythingllm_data/storage 2>/dev/null || true
rm -rf /opt/anythingllm/server/storage
ln -sfn /opt/anythingllm_data/storage /opt/anythingllm/server/storage
cat <<EOF >/opt/anythingllm/server/.env
SERVER_PORT=3001
STORAGE_DIR="/opt/anythingllm/server/storage"
JWT_SECRET="$(openssl rand -hex 32)"
SIG_KEY="$(openssl rand -hex 32)"
SIG_SALT="$(openssl rand -hex 32)"
VECTOR_DB="lancedb"
EOF
cat <<EOF >/opt/anythingllm/collector/.env
STORAGE_DIR="/opt/anythingllm/server/storage"
EOF
cat <<EOF >/opt/anythingllm/frontend/.env
VITE_API_BASE='/api'
EOF
msg_ok "Configured AnythingLLM"
msg_info "Building AnythingLLM (Patience)"
cd /opt/anythingllm
export PUPPETEER_SKIP_DOWNLOAD=true
export NODE_OPTIONS="--max-old-space-size=3072"
$STD yarn setup
cd /opt/anythingllm/frontend
$STD yarn build
cp -R /opt/anythingllm/frontend/dist /opt/anythingllm/server/public
cd /opt/anythingllm/server
$STD npx prisma generate --schema=./prisma/schema.prisma
$STD npx prisma migrate deploy --schema=./prisma/schema.prisma
msg_ok "Built AnythingLLM"
msg_info "Creating Services"
cat <<EOF >/etc/systemd/system/anythingllm.service
[Unit]
Description=AnythingLLM Server
Wants=network-online.target
After=network-online.target
[Service]
Type=simple
User=root
WorkingDirectory=/opt/anythingllm/server
Environment=NODE_ENV=production
ExecStart=/usr/bin/node index.js
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
cat <<EOF >/etc/systemd/system/anythingllm-collector.service
[Unit]
Description=AnythingLLM Collector
Wants=network-online.target
After=network-online.target anythingllm.service
[Service]
Type=simple
User=root
WorkingDirectory=/opt/anythingllm/collector
Environment=NODE_ENV=production
Environment=PUPPETEER_EXECUTABLE_PATH=/usr/bin/chromium
ExecStart=/usr/bin/node index.js
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
systemctl enable -q --now anythingllm anythingllm-collector
msg_ok "Created Services"
motd_ssh
customize
cleanup_lxc

View File

@@ -17,7 +17,8 @@ msg_info "Installing Aria2"
$STD apt install -y aria2
msg_ok "Installed Aria2"
read -r -p "${TAB3}Would you like to add AriaNG? <y/N> " prompt
prompt="${var_aria2_ariang:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add AriaNG? <y/N> " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
msg_info "Installing Dependencies"
$STD apt install -y nginx

View File

@@ -20,16 +20,7 @@ $STD apt install -y \
msg_ok "Installed Dependencies"
RELEASE=$(get_latest_github_release "bunkerity/bunkerweb")
msg_warn "WARNING: This script will run an external installer from a third-party source (install-bunkerweb.sh)."
msg_warn "The following code is NOT maintained or audited by our repository."
msg_warn "If you have any doubts or concerns, please review the installer code before proceeding:"
msg_custom "${TAB3}${GATEWAY}${BGN}${CL}" "\e[1;34m" "→ https://github.com/bunkerity/bunkerweb/raw/v${RELEASE}/misc/install-bunkerweb.sh"
echo
read -r -p "${TAB3}Do you want to continue? [y/N]: " CONFIRM
if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
msg_error "Aborted by user. No changes have been made."
exit 10
fi
confirm_external_installer "install-bunkerweb.sh" "https://github.com/bunkerity/bunkerweb/raw/v${RELEASE}/misc/install-bunkerweb.sh"
msg_info "Installing BunkerWeb (Patience)"
curl -fsSL -o install-bunkerweb.sh "https://github.com/bunkerity/bunkerweb/raw/v${RELEASE}/misc/install-bunkerweb.sh"
chmod +x install-bunkerweb.sh

View File

@@ -24,7 +24,8 @@ cd /opt/bytestash/client
$STD npm install
msg_ok "Installed ByteStash"
read -rp "${TAB3}Do you want to allow registration of multiple accounts? [y/n]: " allowreg
allowreg="${var_bytestash_registration:-}"
[[ -n "$allowreg" ]] || read -rp "${TAB3}Do you want to allow registration of multiple accounts? [y/n]: " allowreg
msg_info "Creating Service"
cat <<EOF >/etc/systemd/system/bytestash-backend.service
@@ -42,7 +43,7 @@ Environment=JWT_SECRET=$JWT_SECRET
WantedBy=multi-user.target
EOF
if [[ "$allowreg" =~ ^[Yy]$ ]]; then
if [[ "${allowreg,,}" =~ ^(y|yes)$ ]]; then
sed -i '8i\Environment=ALLOW_NEW_ACCOUNTS=true' /etc/systemd/system/bytestash-backend.service
fi

View File

@@ -30,7 +30,8 @@ setup_deb_based() {
$STD apt install -y caddy
msg_ok "Installed Caddy"
read -r -p "${TAB3}Would you like to install xCaddy Addon? <y/N> " prompt
prompt="${var_caddy_xcaddy:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to install xCaddy Addon? <y/N> " prompt
if [[ "${prompt,,}" =~ ^(y|yes)$ ]]; then
setup_go
fetch_and_deploy_gh_release "xcaddy" "caddyserver/xcaddy" "binary"
@@ -75,7 +76,8 @@ EOF
EOF
msg_ok "Installed Caddy"
read -r -p "${TAB3}Would you like to install xCaddy Addon? <y/N> " prompt
prompt="${var_caddy_xcaddy:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to install xCaddy Addon? <y/N> " prompt
if [[ "${prompt,,}" =~ ^(y|yes)$ ]]; then
GO_VERSION="$(curl -fsSL https://go.dev/VERSION?m=text | head -1 | cut -c3-)" setup_go
fetch_and_deploy_gh_release "xcaddy" "caddyserver/xcaddy" "prebuild" "latest" "/opt/xcaddy" "xcaddy_*_linux_$(arch_resolve).tar.gz"

View File

@@ -13,16 +13,7 @@ setting_up_container
network_check
update_os
msg_warn "WARNING: This script will run an external installer from a third-party source (https://casaos.zimaspace.com/)."
msg_warn "The following code is NOT maintained or audited by our repository."
msg_warn "If you have any doubts or concerns, please review the installer code before proceeding:"
msg_custom "${TAB3}${GATEWAY}${BGN}${CL}" "\e[1;34m" "→ https://get.casaos.io/"
echo
read -r -p "${TAB3}Do you want to continue? [y/N]: " CONFIRM
if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
msg_error "Aborted by user. No changes have been made."
exit 10
fi
confirm_external_installer "https://casaos.zimaspace.com/" "https://get.casaos.io/"
msg_info "Installing CasaOS (Patience)"
DOCKER_CONFIG_PATH='/etc/docker/daemon.json'
mkdir -p $(dirname $DOCKER_CONFIG_PATH)

View File

@@ -0,0 +1,69 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: fabriziosalmi
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/fabriziosalmi/certmate
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
PYTHON_VERSION="3.12" setup_uv
fetch_and_deploy_gh_release "certmate" "fabriziosalmi/certmate" "tarball"
msg_info "Installing CertMate Dependencies"
cd /opt/certmate
$STD uv venv --python 3.12 /opt/certmate/.venv
# requirements.lock is the fully pinned set the official image is built from
$STD uv pip sync --python /opt/certmate/.venv/bin/python requirements.lock
$STD /opt/certmate/.venv/bin/certbot --version
msg_ok "Installed CertMate Dependencies"
msg_info "Configuring CertMate"
mkdir -p /opt/certmate_data/{certificates,data,backups,logs}
cat <<EOF >/opt/certmate_data/.env
API_BEARER_TOKEN=$(openssl rand -hex 32)
SECRET_KEY=$(openssl rand -hex 32)
CERTMATE_BACKUP_PASSPHRASE=$(openssl rand -hex 32)
BEHIND_PROXY=false
EOF
chmod 600 /opt/certmate_data/.env
msg_ok "Configured CertMate"
msg_info "Creating Service"
cat <<EOF >/etc/systemd/system/certmate.service
[Unit]
Description=CertMate SSL Certificate Manager
After=network-online.target
Wants=network-online.target
[Service]
Type=simple
User=root
WorkingDirectory=/opt/certmate
Environment=PATH=/opt/certmate/.venv/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
Environment=CERTMATE_CERT_DIR=/opt/certmate_data/certificates
Environment=CERTMATE_DATA_DIR=/opt/certmate_data/data
Environment=CERTMATE_BACKUP_DIR=/opt/certmate_data/backups
Environment=CERTMATE_LOGS_DIR=/opt/certmate_data/logs
Environment=ACME_CHALLENGES_DIR=/opt/certmate_data/data/acme-challenges
EnvironmentFile=/opt/certmate_data/.env
# One worker: the renewal scheduler, sessions and rate limits live in-process
ExecStart=/opt/certmate/.venv/bin/gunicorn --bind 0.0.0.0:8000 --workers 1 --threads 8 --timeout 300 --no-control-socket app:app
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
systemctl enable -q --now certmate
msg_ok "Created Service"
motd_ssh
customize
cleanup_lxc

View File

@@ -19,16 +19,7 @@ $STD apt install -y \
xvfb
msg_ok "Installed Dependencies"
msg_warn "WARNING: This script will run an external installer from a third-party source (https://getchannels.com)."
msg_warn "The following code is NOT maintained or audited by our repository."
msg_warn "If you have any doubts or concerns, please review the installer code before proceeding:"
msg_custom "${TAB3}${GATEWAY}${BGN}${CL}" "\e[1;34m" "→ https://getchannels.com/dvr/setup.sh"
echo
read -r -p "${TAB3}Do you want to continue? [y/N]: " CONFIRM
if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
msg_error "Aborted by user. No changes have been made."
exit 10
fi
confirm_external_installer "https://getchannels.com" "https://getchannels.com/dvr/setup.sh"
setup_hwaccel

View File

@@ -0,0 +1,84 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/MoldyTaint/Cinephage
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
msg_info "Installing Dependencies"
$STD apt install -y \
build-essential \
python3 \
libasound2t64 \
libgtk-3-0t64 \
libx11-xcb1 \
xvfb
msg_ok "Installed Dependencies"
setup_ffmpeg
NODE_VERSION="24" setup_nodejs
fetch_and_deploy_gh_release "cinephage" "MoldyTaint/Cinephage" "tarball"
msg_info "Building Cinephage"
cd /opt/cinephage
$STD npm ci
$STD npm run build
$STD npm prune --omit=dev
msg_ok "Built Cinephage"
msg_info "Installing Camoufox"
$STD /opt/cinephage/node_modules/.bin/camoufox-js fetch
msg_ok "Installed Camoufox"
msg_info "Configuring Cinephage"
mkdir -p /opt/cinephage_data/indexers/custom /opt/cinephage_data/external-lists/custom
cat <<EOF >/opt/cinephage_data/.env
NODE_ENV=production
HOST=0.0.0.0
PORT=3000
APP_VERSION=$(cat ~/.cinephage)
BETTER_AUTH_SECRET=$(openssl rand -base64 32)
DATA_DIR=/opt/cinephage_data
INDEXER_DEFINITIONS_PATH=/opt/cinephage/data/indexers/definitions
INDEXER_CUSTOM_DEFINITIONS_PATH=/opt/cinephage_data/indexers/custom
EXTERNAL_LISTS_PRESETS_PATH=/opt/cinephage/data/external-lists/presets
EXTERNAL_LISTS_CUSTOM_PRESETS_PATH=/opt/cinephage_data/external-lists/custom
CAPTCHA_ADDON_PATH=/opt/cinephage/src/lib/server/captcha/browser/addon
FFPROBE_PATH=/usr/bin/ffprobe
EOF
chmod 600 /opt/cinephage_data/.env
msg_ok "Configured Cinephage"
msg_info "Creating Service"
cat <<EOF >/etc/systemd/system/cinephage.service
[Unit]
Description=Cinephage
After=network.target
[Service]
Type=simple
User=root
WorkingDirectory=/opt/cinephage
EnvironmentFile=/opt/cinephage_data/.env
Environment=NODE_OPTIONS=--max-old-space-size=2048
ExecStart=/usr/bin/node server.js
Restart=on-failure
RestartSec=10
[Install]
WantedBy=multi-user.target
EOF
systemctl enable -q --now cinephage
msg_ok "Created Service"
motd_ssh
customize
cleanup_lxc

View File

@@ -31,7 +31,10 @@ sed -i "s/root//g" /etc/cockpit/disallowed-users
msg_ok "Installed Cockpit"
# 45Drives only publishes amd64 packages
[[ "$(arch_resolve)" == "arm64" ]] || read -r -p "Would you like to install 45Drives' cockpit-file-sharing, cockpit-identities, and cockpit-navigator <y/N> " prompt
if [[ "$(arch_resolve)" != "arm64" ]]; then
prompt="${var_cockpit_45drives:-}"
[[ -n "$prompt" ]] || read -r -p "Would you like to install 45Drives' cockpit-file-sharing, cockpit-identities, and cockpit-navigator <y/N> " prompt
fi
if [[ "${prompt,,}" =~ ^(y|yes)$ ]]; then
msg_info "Installing 45Drives' cockpit extensions"
setup_deb822_repo "45drives" \

View File

@@ -19,14 +19,15 @@ msg_ok "Installed Dependencies"
NODE_VERSION="22" setup_nodejs
read -rp "${TAB3}Install OnlyOffice components instead of CKEditor? (Y/N): " onlyoffice
onlyoffice="${var_cryptpad_onlyoffice:-}"
[[ -n "$onlyoffice" ]] || read -rp "${TAB3}Install OnlyOffice components instead of CKEditor? (Y/N): " onlyoffice
fetch_and_deploy_gh_release "cryptpad" "cryptpad/cryptpad" "tarball"
msg_info "Setup CryptPad"
cd /opt/cryptpad
$STD npm ci --allow-git=all
$STD npm run install:components
if [[ "$onlyoffice" =~ ^[Yy]$ ]]; then
if [[ "${onlyoffice,,}" =~ ^(y|yes)$ ]]; then
$STD bash -c "./install-onlyoffice.sh --accept-license"
fi
cp config/config.example.js config/config.js

View File

@@ -15,12 +15,16 @@ update_os
setup_deb_based() {
setup_docker
read -r -p "${TAB3}Expose Docker TCP socket (insecure) ? [n = No, l = Local only (127.0.0.1), a = All interfaces (0.0.0.0)] <n/l/a>: " socket_choice
if [[ -n "${var_docker_socket:-}" ]]; then
socket_choice="$var_docker_socket"
else
read -r -p "${TAB3}Expose Docker TCP socket (insecure) ? [n = No, l = Local only (127.0.0.1), a = All interfaces (0.0.0.0)] <n/l/a>: " socket_choice
fi
case "${socket_choice,,}" in
l)
l | local)
socket="tcp://127.0.0.1:2375"
;;
a)
a | all)
socket="tcp://0.0.0.0:2375"
;;
*)
@@ -66,8 +70,12 @@ setup_alpine() {
msg_ok "Installed Docker"
DOCKER_COMPOSE_LATEST_VERSION=$(get_latest_github_release "docker/compose" false)
read -r -p "${TAB3}Would you like to add Docker Compose? <y/N> " prompt
if [[ "${prompt,,}" =~ ^(y|yes)$ ]]; then
if [[ -n "${var_docker_compose:-}" ]]; then
prompt="$var_docker_compose"
else
read -r -p "${TAB3}Would you like to add Docker Compose? <y/N> " prompt
fi
if [[ "${prompt,,}" =~ ^(y|yes|true)$ ]]; then
msg_info "Installing Docker Compose $DOCKER_COMPOSE_LATEST_VERSION"
DOCKER_CONFIG=${DOCKER_CONFIG:-$HOME/.docker}
mkdir -p "$DOCKER_CONFIG"/cli-plugins
@@ -75,13 +83,23 @@ setup_alpine() {
chmod +x "$DOCKER_CONFIG"/cli-plugins/docker-compose
msg_ok "Installed Docker Compose $DOCKER_COMPOSE_LATEST_VERSION"
fi
read -r -p "${TAB3}Would you like to expose the Docker TCP socket? <y/N> " prompt
if [[ "${prompt,,}" =~ ^(y|yes)$ ]]; then
msg_info "Exposing Docker TCP socket"
$STD mkdir -p /etc/docker
$STD echo '{ "hosts": ["unix:///var/run/docker.sock", "tcp://0.0.0.0:2375"] }' >/etc/docker/daemon.json
if [[ -n "${var_docker_socket:-}" ]]; then
prompt="$var_docker_socket"
else
read -r -p "${TAB3}Would you like to expose the Docker TCP socket? <y/N> " prompt
fi
case "${prompt,,}" in
y | yes | a | all) socket="tcp://0.0.0.0:2375" ;;
l | local) socket="tcp://127.0.0.1:2375" ;;
*) socket="" ;;
esac
if [[ -n "$socket" ]]; then
msg_info "Exposing Docker TCP socket on $socket"
mkdir -p /etc/docker
# No $STD here: silent() captures stdout, which left daemon.json empty.
printf '{ "hosts": ["unix:///var/run/docker.sock", "%s"] }\n' "$socket" >/etc/docker/daemon.json
$STD rc-service docker restart
msg_ok "Exposed Docker TCP socket at tcp://+:2375"
msg_ok "Exposed Docker TCP socket on $socket"
fi
}

View File

@@ -38,7 +38,8 @@ rm -f "$DEB_FILE"
echo "$LATEST_VERSION" >~/.emqx
msg_ok "Installed EMQX"
read -r -p "${TAB3}Would you like to disable the EMQX MQ feature? (reduces disk/CPU usage) <y/N> " prompt
prompt="${var_emqx_disable_mq:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to disable the EMQX MQ feature? (reduces disk/CPU usage) <y/N> " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
msg_info "Disabling EMQX MQ feature"
mkdir -p /etc/emqx

View File

@@ -21,7 +21,7 @@ PYTHON_VERSION="3.13" setup_uv
NODE_VERSION="24" setup_nodejs
PG_VERSION="17" PG_MODULES="postgis" setup_postgresql
PG_DB_NAME="enduraindb" PG_DB_USER="endurain" setup_postgresql_db
fetch_and_deploy_codeberg_release "endurain" "endurain-project/endurain" "tarball" "latest" "/opt/endurain"
fetch_and_deploy_gh_release "endurain" "endurain-project/endurain"
msg_info "Setting up Endurain"
cd /opt/endurain

View File

@@ -0,0 +1,49 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ) | Co-Author: 007hacky007
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/FoldingAtHome/fah-client-bastet
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
if [[ -z "${var_fah_token:-}" ]]; then
var_fah_token=$(prompt_password "Folding@home account token (Enter to skip):" "" 120)
fi
if [[ -z "${var_fah_machine_name:-}" ]]; then
var_fah_machine_name=$(prompt_input "Folding@home machine name:" "$(hostname)" 60)
fi
if [[ ${#var_fah_machine_name} -gt 64 || "$var_fah_machine_name" == *[\<\>\;\&\'\"]* ]]; then
msg_warn "Machine name must be 1-64 characters without <>;&'\" - using $(hostname)"
var_fah_machine_name=$(hostname)
fi
msg_info "Configuring Folding@home"
mkdir -p /etc/fah-client
cat <<EOF >/etc/fah-client/config.xml
<config>
<account-token v="${var_fah_token}"/>
<machine-name v="${var_fah_machine_name}"/>
</config>
EOF
msg_ok "Configured Folding@home"
fetch_and_deploy_from_url "https://download.foldingathome.org/releases/public/fah-client/$(arch_resolve "debian-10-64bit" "debian-stable-arm64")/release/latest.deb"
setup_hwaccel "fah-client"
# The client detects GPUs only at startup, so restart it after setup_hwaccel.
msg_info "Starting Folding@home"
systemctl enable -q fah-client
safe_service_restart fah-client
msg_ok "Started Folding@home"
motd_ssh
customize
cleanup_lxc

View File

@@ -15,7 +15,8 @@ update_os
fetch_and_deploy_gh_release "headscale" "juanfont/headscale" "binary"
read -r -p "${TAB3}Would you like to add headscale-admin UI? <y/N> " prompt
prompt="${var_headscale_admin:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add headscale-admin UI? <y/N> " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
fetch_and_deploy_gh_release "headscale-admin" "GoodiesHQ/headscale-admin" "prebuild" "latest" "/opt/headscale-admin" "admin.zip"

View File

@@ -33,16 +33,7 @@ NODE_OPTIONS=${NODE_OPTIONS}
EOF
msg_ok "Configured Service Environment"
msg_warn "WARNING: This script will run an external installer from a third-party source (https://hermes-agent.nousresearch.com/)."
msg_warn "The following code is NOT maintained or audited by our repository."
msg_warn "If you have any doubts or concerns, please review the installer code before proceeding:"
msg_custom "${TAB3}${GATEWAY}${BGN}${CL}" "\e[1;34m" "→ https://hermes-agent.nousresearch.com/install.sh"
echo
read -r -p "${TAB3}Do you want to continue? [y/N]: " CONFIRM
if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
msg_error "Aborted by user. No changes have been made."
exit 10
fi
confirm_external_installer "https://hermes-agent.nousresearch.com/" "https://hermes-agent.nousresearch.com/install.sh"
msg_info "Installing Hermes Agent"
curl -fsSL https://hermes-agent.nousresearch.com/install.sh -o /tmp/hermes-install.sh

View File

@@ -84,6 +84,7 @@ $STD apt install --no-install-recommends -y \
liblqr-1-0 \
libltdl7 \
libopenjp2-7 \
libopenjp2-7-dev \
meson \
ninja-build \
pkg-config \
@@ -441,9 +442,11 @@ if [[ -f ~/.openvino ]]; then
msg_ok "Pre-installed Python ${ML_PYTHON}"
msg_info "Installing Intel OpenVINO machine-learning"
for attempt in $(seq 1 3); do
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT -Pnu immich uv sync --extra openvino --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT,UV_CONCURRENT_DOWNLOADS,UV_CONCURRENT_BUILDS,UV_CONCURRENT_INSTALLS -Pnu immich uv sync --extra openvino --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
[[ $attempt -eq 3 ]] && { msg_error "uv sync failed three times, the machine-learning environment was not built"; exit 1; }
msg_warn "uv sync attempt $attempt failed, retrying..." && sleep 10
# Parallel fetches can trip DNS rate limits (AdGuard, Pi-hole); retry one at a time.
export UV_CONCURRENT_DOWNLOADS=1 UV_CONCURRENT_BUILDS=1 UV_CONCURRENT_INSTALLS=1
msg_warn "uv sync attempt $attempt failed, retrying one download at a time..." && sleep 10
done
patchelf --clear-execstack "${VIRTUAL_ENV}/lib/python3.13/site-packages/onnxruntime/capi/onnxruntime_pybind11_state.cpython-313-$(arch_resolve "x86_64" "aarch64")-linux-gnu.so"
msg_ok "Installed Intel OpenVINO machine-learning"
@@ -457,9 +460,11 @@ else
msg_ok "Pre-installed Python ${ML_PYTHON}"
msg_info "Installing machine-learning"
for attempt in $(seq 1 3); do
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT -Pnu immich uv sync --extra cpu --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT,UV_CONCURRENT_DOWNLOADS,UV_CONCURRENT_BUILDS,UV_CONCURRENT_INSTALLS -Pnu immich uv sync --extra cpu --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
[[ $attempt -eq 3 ]] && { msg_error "uv sync failed three times, the machine-learning environment was not built"; exit 1; }
msg_warn "uv sync attempt $attempt failed, retrying..." && sleep 10
# Parallel fetches can trip DNS rate limits (AdGuard, Pi-hole); retry one at a time.
export UV_CONCURRENT_DOWNLOADS=1 UV_CONCURRENT_BUILDS=1 UV_CONCURRENT_INSTALLS=1
msg_warn "uv sync attempt $attempt failed, retrying one download at a time..." && sleep 10
done
msg_ok "Installed machine-learning"
fi

View File

@@ -50,7 +50,8 @@ else
fi
msg_ok "Installed InfluxDB"
read -r -p "${TAB3}Would you like to add Telegraf? <y/N> " prompt
prompt="${var_influxdb_telegraf:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add Telegraf? <y/N> " prompt
if [[ "${prompt,,}" =~ ^(y|yes)$ ]]; then
msg_info "Installing Telegraf"
$STD apt install -y telegraf

View File

@@ -17,16 +17,7 @@ msg_info "Installing Dependencies"
$STD apt install -y ca-certificates
msg_ok "Installed Dependencies"
msg_warn "WARNING: This script will run an external installer from a third-party source (https://iobroker.net/)."
msg_warn "The following code is NOT maintained or audited by our repository."
msg_warn "If you have any doubts or concerns, please review the installer code before proceeding:"
msg_custom "${TAB3}${GATEWAY}${BGN}${CL}" "\e[1;34m" "→ https://iobroker.net/install.sh"
echo
read -r -p "${TAB3}Do you want to continue? [y/N]: " CONFIRM
if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
msg_error "Aborted by user. No changes have been made."
exit 10
fi
confirm_external_installer "https://iobroker.net/" "https://iobroker.net/install.sh"
NODE_VERSION="24" NPM_VERSION="11" setup_nodejs

View File

@@ -56,16 +56,7 @@ if [[ -z "$KASM_VERSION" ]] || [[ -z "$KASM_URL" ]]; then
fi
msg_ok "Detected Kasm Workspaces version $KASM_VERSION"
msg_warn "WARNING: This script will run an external installer from a third-party source (https://www.kasmweb.com/)."
msg_warn "The following code is NOT maintained or audited by our repository."
msg_warn "If you have any doubts or concerns, please review the installer code before proceeding:"
msg_custom "${TAB3}${GATEWAY}${BGN}${CL}" "\e[1;34m" "→ install.sh inside tar.gz $KASM_URL"
echo
read -r -p "${TAB3}Do you want to continue? [y/N]: " CONFIRM
if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
msg_error "Aborted by user. No changes have been made."
exit 10
fi
confirm_external_installer "https://www.kasmweb.com/" "install.sh inside tar.gz $KASM_URL"
msg_info "Installing Kasm Workspaces"
curl_download "/opt/kasm_release_${KASM_VERSION}.tar.gz" "$KASM_URL"

View File

@@ -24,7 +24,8 @@ PG_VERSION="16" setup_postgresql
RUST_CRATES="monolith" setup_rust
PG_DB_NAME="linkwardendb" PG_DB_USER="linkwarden" setup_postgresql_db
read -r -p "${TAB3}Would you like to add Adminer? <y/N> " prompt
prompt="${var_linkwarden_adminer:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add Adminer? <y/N> " prompt
if [[ "${prompt,,}" =~ ^(y|yes)$ ]]; then
setup_adminer
fi

View File

@@ -28,16 +28,7 @@ export HOME=/opt/livebook
$STD adduser --system --group --home /opt/livebook --shell /bin/bash livebook
msg_ok "Created livebook user"
msg_warn "WARNING: This script will run an external installer from a third-party source (https://elixir-lang.org)."
msg_warn "The following code is NOT maintained or audited by our repository."
msg_warn "If you have any doubts or concerns, please review the installer code before proceeding:"
msg_custom "${TAB3}${GATEWAY}${BGN}${CL}" "\e[1;34m" "→ https://elixir-lang.org/install.sh"
echo
read -r -p "${TAB3}Do you want to continue? [y/N]: " CONFIRM
if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
msg_error "Aborted by user. No changes have been made."
exit 10
fi
confirm_external_installer "https://elixir-lang.org" "https://elixir-lang.org/install.sh"
curl -fsSO https://elixir-lang.org/install.sh
$STD sh install.sh elixir@latest otp@latest

View File

@@ -0,0 +1,92 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: Bryan Lieberman (BryanCLieberman)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://localai.io
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
msg_info "Installing Dependencies"
$STD apt install -y \
libgomp1 \
libopenblas0
msg_ok "Installed Dependencies"
setup_hwaccel
var_port="${var_port:-8080}"
var_auth="${var_auth:-no}"
var_api_key="${var_api_key:-}"
if [[ "$var_auth" == "yes" ]]; then
setup_postgresql
PG_DB_NAME="localai" PG_DB_USER="localai" setup_postgresql_db
fi
fetch_and_deploy_gh_release "localai" "mudler/LocalAI" "singlefile" "latest" "/opt/localai" "local-ai-v*-linux-$(arch_resolve amd64 arm64)"
msg_info "Configuring LocalAI"
mkdir -p /opt/localai_data/models /opt/localai_data/backends
cat <<EOF >/opt/localai.env
LOCALAI_ADDRESS=0.0.0.0:${var_port}
LOCALAI_DATA_PATH=/opt/localai_data
LOCALAI_MODELS_PATH=/opt/localai_data/models
LOCALAI_BACKENDS_PATH=/opt/localai_data/backends
LOCALAI_LOG_LEVEL=info
EOF
# LocalAI refuses to start on a wildcard bind with nothing to identify callers,
# and binding the wildcard is what makes the container reachable at all.
if [[ "$var_auth" == "yes" ]]; then
cat <<EOF >>/opt/localai.env
LOCALAI_AUTH=true
LOCALAI_AUTH_DATABASE_URL=postgres://${PG_DB_USER}:${PG_DB_PASS}@localhost/${PG_DB_NAME}
LOCALAI_REGISTRATION_MODE=approval
EOF
fi
# A static key grants admin access on its own, so when it is the only thing
# guarding the API, generate one rather than leaving the server open.
if [[ -z "$var_api_key" && "$var_auth" != "yes" ]]; then
var_api_key="sk-$(openssl rand -hex 24)"
{
echo "LocalAI Credentials"
echo "API Key: ${var_api_key}"
} >>~/localai.creds
fi
if [[ -n "$var_api_key" ]]; then
echo "LOCALAI_API_KEY=${var_api_key}" >>/opt/localai.env
else
echo "#LOCALAI_API_KEY=" >>/opt/localai.env
fi
chmod 600 /opt/localai.env
msg_ok "Configured LocalAI"
msg_info "Creating Service"
cat <<EOF >/etc/systemd/system/localai.service
[Unit]
Description=LocalAI Server
Wants=network-online.target
After=network-online.target
[Service]
Type=simple
User=root
WorkingDirectory=/opt/localai
EnvironmentFile=/opt/localai.env
ExecStart=/opt/localai/localai run
Restart=on-failure
RestartSec=10
[Install]
WantedBy=multi-user.target
EOF
systemctl enable -q --now localai
msg_ok "Created Service"
motd_ssh
customize
cleanup_lxc

View File

@@ -21,7 +21,8 @@ setup_deb_based() {
sed -i 's/^bind-address/#bind-address/g' /etc/mysql/mariadb.conf.d/50-server.cnf
msg_ok "Setup MariaDB"
read -r -p "${TAB3}Would you like to add PhpMyAdmin? <y/N> " prompt
prompt="${var_mariadb_phpmyadmin:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add PhpMyAdmin? <y/N> " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
msg_info "Installing phpMyAdmin"
$STD apt install -y \
@@ -58,7 +59,8 @@ setup_alpine() {
$STD rc-service mariadb start
msg_ok "MariaDB Configured"
read -r -p "${TAB3}Would you like to install Adminer with lighttpd? <y/N>: " prompt
prompt="${var_mariadb_adminer:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to install Adminer with lighttpd? <y/N>: " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
msg_info "Installing Adminer and dependencies"
$STD apk add --no-cache \

View File

@@ -13,16 +13,7 @@ setting_up_container
network_check
update_os
msg_warn "WARNING: This script will run an external installer from a third-party source (https://mattermost.com/)."
msg_warn "The following code is NOT maintained or audited by our repository."
msg_warn "If you have any doubts or concerns, please review the installer code before proceeding:"
msg_custom "${TAB3}${GATEWAY}${BGN}${CL}" "\e[1;34m" "→ https://deb.packages.mattermost.com/repo-setup.sh"
echo
read -r -p "${TAB3}Do you want to continue? [y/N]: " CONFIRM
if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
msg_error "Aborted by user. No changes have been made."
exit 10
fi
confirm_external_installer "https://mattermost.com/" "https://deb.packages.mattermost.com/repo-setup.sh"
PG_VERSION="16" setup_postgresql

View File

@@ -15,7 +15,8 @@ update_os
MEILISEARCH_BIND="0.0.0.0:7700" setup_meilisearch
read -r -p "${TAB3}Do you want add meilisearch-ui? [y/n]: " prompt
prompt="${var_meilisearch_ui:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Do you want add meilisearch-ui? [y/n]: " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
NODE_VERSION="22" NODE_MODULE="pnpm@latest" setup_nodejs
fetch_and_deploy_gh_release "meilisearch-ui" "riccox/meilisearch-ui" "tarball"

View File

@@ -13,16 +13,7 @@ setting_up_container
network_check
update_os
msg_warn "WARNING: This script will run an external installer from a third-party source (https://nextcloudpi.com/)."
msg_warn "The following code is NOT maintained or audited by our repository."
msg_warn "If you have any doubts or concerns, please review the installer code before proceeding:"
msg_custom "${TAB3}${GATEWAY}${BGN}${CL}" "\e[1;34m" "→ https://raw.githubusercontent.com/nextcloud/nextcloudpi/master/install.sh"
echo
read -r -p "${TAB3}Do you want to continue? [y/N]: " CONFIRM
if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
msg_error "Aborted by user. No changes have been made."
exit 10
fi
confirm_external_installer "https://nextcloudpi.com/" "https://raw.githubusercontent.com/nextcloud/nextcloudpi/master/install.sh"
msg_info "Making ssh.service reloads behave like restarts"
mkdir -p /etc/systemd/system/ssh.service.d

View File

@@ -207,7 +207,7 @@ EOF
$STD sudo -u cool coolconfig set ssl.enable false
$STD sudo -u cool coolconfig set ssl.termination true
$STD sudo -u cool coolconfig set ssl.ssl_verification true
sed -i "s|-Policy\">|&frame-ancestors https://${OPENCLOUD_FQDN}|" /etc/coolwsd/coolwsd.xml
$STD sudo -u cool coolconfig set net.frame_ancestors "https://${OPENCLOUD_FQDN}"
useradd -r -M -s /usr/sbin/nologin opencloud
chown -R opencloud:opencloud "$CONFIG_DIR" "$DATA_DIR"
sudo -u opencloud opencloud init --config-path "$CONFIG_DIR" --insecure no

View File

@@ -26,7 +26,8 @@ setup_hwaccel
PYTHON_VERSION="3.12" setup_uv
OTEL_ARGS=()
read -r -p "${TAB3}Would you like to install OpenTelemetry instrumentation packages (requires manual .env configuration)? <y/N> " prompt
prompt="${var_openwebui_otel:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to install OpenTelemetry instrumentation packages (requires manual .env configuration)? <y/N> " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
for pkg in \
opentelemetry-api \
@@ -52,7 +53,8 @@ for attempt in $(seq 1 3); do
done
msg_ok "Installed Open WebUI"
read -r -p "${TAB3}Would you like to add Ollama? <y/N> " prompt
prompt="${var_openwebui_ollama:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add Ollama? <y/N> " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
if [[ "$(arch_resolve)" == "amd64" ]]; then
msg_info "Setting up Intel® Repositories"

View File

@@ -163,7 +163,8 @@ EOF
systemctl enable -q --now paperless-webserver paperless-scheduler paperless-task-queue paperless-consumer
msg_ok "Created Services"
read -r -p "${TAB3}Would you like to add Adminer? <y/N> " prompt
prompt="${var_paperless_ngx_adminer:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add Adminer? <y/N> " prompt
if [[ "${prompt,,}" =~ ^(y|yes)$ ]]; then
setup_adminer
fi

View File

@@ -13,16 +13,7 @@ setting_up_container
network_check
update_os
msg_warn "WARNING: This script will run an external installer from a third-party source (https://pi-hole.net/)."
msg_warn "The following code is NOT maintained or audited by our repository."
msg_warn "If you have any doubts or concerns, please review the installer code before proceeding:"
msg_custom "${TAB3}${GATEWAY}${BGN}${CL}" "\e[1;34m" "→ https://install.pi-hole.net"
echo
read -r -p "${TAB3}Do you want to continue? [y/N]: " CONFIRM
if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
msg_error "Aborted by user. No changes have been made."
exit 10
fi
confirm_external_installer "https://pi-hole.net/" "https://install.pi-hole.net"
msg_info "Installing Dependencies"
$STD apt install -y ufw
@@ -65,9 +56,11 @@ $STD pihole-FTL --config ntp.sync.interval 0
systemctl restart pihole-FTL.service
msg_ok "Installed Pi-hole"
read -r -p "${TAB3}Would you like to add Unbound? <y/N> " prompt
prompt="${var_pihole_unbound:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add Unbound? <y/N> " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
read -r -p "${TAB3}Unbound is configured as a recursive DNS server by default, would you like it to be configured as a forwarding DNS server (using DNS-over-TLS (DoT)) instead? <y/N> " prompt
prompt="${var_pihole_unbound_dot:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Unbound is configured as a recursive DNS server by default, would you like it to be configured as a forwarding DNS server (using DNS-over-TLS (DoT)) instead? <y/N> " prompt
msg_info "Installing Unbound"
mkdir -p /etc/unbound/unbound.conf.d
cat <<EOF >/etc/unbound/unbound.conf.d/pi-hole.conf

View File

@@ -48,7 +48,8 @@ msg_ok "Installed Podman"
mkdir -p /etc/containers/systemd
read -r -p "${TAB3}Would you like to add Portainer? <y/N> " prompt
prompt="${var_podman_homeassistant_portainer:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add Portainer? <y/N> " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
msg_info "Installing Portainer $PORTAINER_LATEST_VERSION"
podman volume create portainer_data >/dev/null
@@ -75,7 +76,8 @@ EOF
$STD systemctl start portainer
msg_ok "Installed Portainer $PORTAINER_LATEST_VERSION"
else
read -r -p "${TAB3}Would you like to add the Portainer Agent? <y/N> " prompt
prompt="${var_podman_homeassistant_portainer_agent:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add the Portainer Agent? <y/N> " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
msg_info "Installing Portainer agent $PORTAINER_AGENT_LATEST_VERSION"
cat <<EOF >/etc/containers/systemd/portainer-agent.container

View File

@@ -48,7 +48,8 @@ msg_ok "Installed Podman"
mkdir -p /etc/containers/systemd
read -r -p "${TAB3}Would you like to add Portainer? <y/N> " prompt
prompt="${var_podman_portainer:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add Portainer? <y/N> " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
msg_info "Installing Portainer $PORTAINER_LATEST_VERSION"
podman volume create portainer_data >/dev/null
@@ -76,7 +77,8 @@ EOF
$STD systemctl start portainer
msg_ok "Installed Portainer $PORTAINER_LATEST_VERSION"
else
read -r -p "${TAB3}Would you like to add the Portainer Agent? <y/N> " prompt
prompt="${var_podman_portainer_agent:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add the Portainer Agent? <y/N> " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
msg_info "Installing Portainer agent $PORTAINER_AGENT_LATEST_VERSION"
$STD podman pull docker.io/portainer/agent:latest

View File

@@ -124,7 +124,8 @@ EOF
systemctl restart postgresql
msg_ok "Installed PostgreSQL"
read -r -p "${TAB3}Would you like to add Adminer? <y/N> " prompt
prompt="${var_postgresql_adminer:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add Adminer? <y/N> " prompt
if [[ "${prompt,,}" =~ ^(y|yes)$ ]]; then
msg_info "Installing Adminer"
$STD apt install -y adminer
@@ -158,7 +159,8 @@ setup_alpine() {
$STD rc-service postgresql restart
msg_ok "Configured and Restarted PostgreSQL"
read -r -p "${TAB3}Would you like to install Adminer with lighttpd? <y/N>: " prompt
prompt="${var_postgresql_adminer:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to install Adminer with lighttpd? <y/N>: " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
msg_info "Installing Adminer and dependencies"
$STD apk add --no-cache \

View File

@@ -58,7 +58,7 @@ Requires=network.target
[Service]
WorkingDirectory=/opt/radicale
ExecStart=/usr/local/bin/uv run -m radicale --config /etc/radicale/config
ExecStart=/usr/local/bin/uv run --extra bcrypt --extra argon2 -m radicale --config /etc/radicale/config
Restart=on-failure
# User=radicale
# Deny other users access to the calendar data

View File

@@ -40,7 +40,8 @@ $STD uv venv --clear /opt/sabnzbd/venv
$STD uv pip install -r /opt/sabnzbd/requirements.txt --python=/opt/sabnzbd/venv/bin/python
msg_ok "Installed SABnzbd"
read -r -p "Would you like to install par2cmdline-turbo? <y/N> " prompt
prompt="${var_sabnzbd_par2_turbo:-}"
[[ -n "$prompt" ]] || read -r -p "Would you like to install par2cmdline-turbo? <y/N> " prompt
if [[ "${prompt,,}" =~ ^(y|yes)$ ]]; then
mv /usr/bin/par2 /usr/bin/par2.old
fetch_and_deploy_gh_release "par2cmdline-turbo" "animetosho/par2cmdline-turbo" "prebuild" "latest" "/usr/bin/" "*-linux-$(arch_resolve).zip"

View File

@@ -17,7 +17,8 @@ fetch_and_deploy_gh_release "silverbullet" "silverbulletmd/silverbullet" "prebui
mkdir -p /opt/silverbullet/space
RUNTIME_API_ENV=""
read -rp "${TAB3}Enable Silverbullet Runtime API? Requires Chromium (~700MB). Uses ~200MB extra RAM. (y/N): " runtime_api_prompt
runtime_api_prompt="${var_silverbullet_runtime_api:-}"
[[ -n "$runtime_api_prompt" ]] || read -rp "${TAB3}Enable Silverbullet Runtime API? Requires Chromium (~700MB). Uses ~200MB extra RAM. (y/N): " runtime_api_prompt
if [[ "${runtime_api_prompt,,}" =~ ^(y|yes)$ ]]; then
msg_info "Installing Chromium for Runtime API"
$STD apt install -y chromium

View File

@@ -36,7 +36,8 @@ sed -i \
-e 's/^.*picture/#&/' /opt/slskd/config/slskd.yml
msg_ok "Configured Slskd"
read -rp "${TAB3}Do you want to install Soularr? y/N " soularr
soularr="${var_slskd_soularr:-}"
[[ -n "$soularr" ]] || read -rp "${TAB3}Do you want to install Soularr? y/N " soularr
if [[ ${soularr,,} =~ ^(y|yes)$ ]]; then
PYTHON_VERSION="3.11" setup_uv
fetch_and_deploy_gh_release "Soularr" "mrusse/soularr" "tarball" "latest" "/opt/soularr"

View File

@@ -34,7 +34,8 @@ msg_ok "Installed Dependencies"
PYTHON_VERSION="3.12" setup_uv
JAVA_VERSION="25" setup_java
if ! read -r -p "${TAB3}Do you want to use Stirling-PDF with Login? (no/n = without Login) [Y/n] " response; then
response="${var_stirling_pdf_login:-}"
if [[ -z "$response" ]] && ! read -r -p "${TAB3}Do you want to use Stirling-PDF with Login? (no/n = without Login) [Y/n] " response; then
# No interactive stdin (EOF): fall back to the no-login install instead of
# silently selecting login, which the -z test below would otherwise do.
response="n"

View File

@@ -105,8 +105,9 @@ setup_alpine() {
$STD apk add traefik --repository=https://dl-cdn.alpinelinux.org/alpine/edge/community
msg_ok "Installed Traefik"
read -p "${TAB3}Enable Traefik WebUI (Port 8080)? [y/N]: " enable_webui
if [[ "$enable_webui" =~ ^[Yy]$ ]]; then
enable_webui="${var_traefik_webui:-}"
[[ -n "$enable_webui" ]] || read -p "${TAB3}Enable Traefik WebUI (Port 8080)? [y/N]: " enable_webui
if [[ "${enable_webui,,}" =~ ^(y|yes)$ ]]; then
msg_info "Configuring Traefik WebUI"
sed -i 's/localhost//g' /etc/traefik/traefik.yaml
msg_ok "Configured Traefik WebUI"

View File

@@ -0,0 +1,46 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: Nicolas Pastorello (opastorello)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://tvheadend.org/ | Github: https://github.com/tvheadend/tvheadend
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
setup_deb822_repo \
"tvheadend" \
"https://dl.cloudsmith.io/public/tvheadend/tvheadend/gpg.C6CC06BD69B430C6.key" \
"https://dl.cloudsmith.io/public/tvheadend/tvheadend/deb/debian" \
"$(get_os_info codename)" \
"main"
var_admin_user="${var_admin_user:-admin}"
var_admin_pass="${var_admin_pass:-$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | cut -c1-13)}"
msg_info "Installing Tvheadend"
echo "tvheadend tvheadend/admin_username string ${var_admin_user}" | debconf-set-selections
echo "tvheadend tvheadend/admin_password password ${var_admin_pass}" | debconf-set-selections
$STD apt install -y tvheadend
msg_ok "Installed Tvheadend"
msg_info "Starting Service"
systemctl enable -q --now tvheadend
msg_ok "Started Service"
msg_info "Saving Credentials"
cat <<EOF >~/tvheadend.creds
Tvheadend Admin Credentials
Username: ${var_admin_user}
Password: ${var_admin_pass}
EOF
msg_ok "Saved Credentials"
motd_ssh
customize
cleanup_lxc

View File

@@ -36,9 +36,11 @@ setup_deb_based() {
msg_ok "Installed Valkey"
echo
read -r -p "${TAB3}Enable TLS for Valkey (Sentinel mode does not supported)? [y/N]: " prompt
prompt="${var_valkey_tls:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Enable TLS for Valkey (Sentinel mode does not supported)? [y/N]: " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
read -r -p "${TAB3}Use TLS-only mode (disable TCP port 6379)? [y/N]: " tls_only
tls_only="${var_valkey_tls_only:-}"
[[ -n "$tls_only" ]] || read -r -p "${TAB3}Use TLS-only mode (disable TCP port 6379)? [y/N]: " tls_only
msg_info "Configuring TLS for Valkey..."
create_self_signed_cert "Valkey"

View File

@@ -16,7 +16,8 @@ update_os
fetch_and_deploy_gh_release "versitygw" "versity/versitygw" "binary"
WEBUI_CONF=""
read -rp "Would you like to enable the VersityGW WebGUI (Beta)? (y/N): " webui_prompt
webui_prompt="${var_versitygw_webgui:-}"
[[ -n "$webui_prompt" ]] || read -rp "Would you like to enable the VersityGW WebGUI (Beta)? (y/N): " webui_prompt
if [[ "${webui_prompt,,}" =~ ^(y|yes)$ ]]; then
WEBUI_CONF="\nVGW_WEBUI_PORT=:7071\nVGW_WEBUI_NO_TLS=true"
msg_ok "WebGUI will be enabled on port 7071"

View File

@@ -27,7 +27,8 @@ msg_ok "Got version $victoriametrics_release of VictoriaMetrics"
fetch_and_deploy_gh_release "victoriametrics" "VictoriaMetrics/VictoriaMetrics" "prebuild" "$victoriametrics_release" "/opt/victoriametrics" "$victoriametrics_filename"
fetch_and_deploy_gh_release "vmutils" "VictoriaMetrics/VictoriaMetrics" "prebuild" "$victoriametrics_release" "/opt/victoriametrics" "$vmutils_filename"
read -r -p "${TAB3}Would you like to add VictoriaLogs? <y/N> " prompt
prompt="${var_victoriametrics_logs:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add VictoriaLogs? <y/N> " prompt
if [[ ${prompt,,} =~ ^(y|yes)$ ]]; then
vl_release_json="$(mktemp)"

View File

@@ -15,16 +15,7 @@ update_os
RELEASE=$(get_latest_github_release "wazuh/wazuh" | cut -d. -f1,2)
msg_warn "WARNING: This script will run an external installer from a third-party source (https://wazuh.com/)."
msg_warn "The following code is NOT maintained or audited by our repository."
msg_warn "If you have any doubts or concerns, please review the installer code before proceeding:"
msg_custom "${TAB3}${GATEWAY}${BGN}${CL}" "\e[1;34m" "→ https://packages.wazuh.com/$RELEASE/wazuh-install.sh "
echo
read -r -p "${TAB3}Do you want to continue? [y/N]: " CONFIRM
if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
msg_error "Aborted by user. No changes have been made."
exit 10
fi
confirm_external_installer "https://wazuh.com/" "https://packages.wazuh.com/$RELEASE/wazuh-install.sh"
msg_info "Setup Wazuh"
curl -fsSL https://packages.wazuh.com/$RELEASE/wazuh-install.sh -o wazuh-install.sh

144
install/weblate-install.sh Normal file
View File

@@ -0,0 +1,144 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/WeblateOrg/weblate
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
msg_info "Installing Dependencies"
$STD apt install -y \
build-essential \
pkg-config \
libacl1-dev \
liblz4-dev \
libzstd-dev \
libxxhash-dev \
libssl-dev \
libldap2-dev \
libsasl2-dev \
git \
gettext \
nginx \
valkey-server
msg_ok "Installed Dependencies"
PG_VERSION="17" setup_postgresql
PG_DB_NAME="weblate" PG_DB_USER="weblate" setup_postgresql_db
PYTHON_VERSION="3.14" setup_uv
USE_ORIGINAL_FILENAME=true fetch_and_deploy_gh_release "weblate" "WeblateOrg/weblate" "singlefile" "latest" "/opt/weblate" "weblate-*-py3-none-any.whl"
msg_info "Installing Weblate"
$STD uv venv --python 3.14 /opt/weblate/.venv
$STD uv pip install --python /opt/weblate/.venv/bin/python --compile-bytecode /opt/weblate/weblate-*.whl "weblate[all,wsgi]"
rm -f /opt/weblate/weblate-*.whl
msg_ok "Installed Weblate"
msg_info "Configuring Weblate"
mkdir -p /opt/weblate_data/python/customize /app
# weblate.settings_docker is upstream's env-driven settings; it reads the secret and
# settings-override.py from /app/data and loads the "customize" app from DATA_DIR/python
ln -sfn /opt/weblate_data /app/data
touch /opt/weblate_data/python/customize/{__init__,models}.py
/opt/weblate/.venv/bin/weblate-generate-secret-key >/opt/weblate_data/secret
cat <<EOF >/opt/weblate_data/weblate.env
DJANGO_SETTINGS_MODULE=weblate.settings_docker
PYTHONPATH=/opt/weblate_data/python
WEBLATE_SITE_DOMAIN=${LOCAL_IP}
WEBLATE_DATA_DIR=/opt/weblate_data
WEBLATE_CACHE_DIR=/opt/weblate/cache
WEBLATE_IP_PROXY_HEADER=HTTP_X_FORWARDED_FOR
POSTGRES_HOST=127.0.0.1
POSTGRES_DB=weblate
POSTGRES_USER=weblate
POSTGRES_PASSWORD=${PG_DB_PASS}
REDIS_HOST=127.0.0.1
# Password set for the "admin" account at install; Weblate does not read it
WEBLATE_ADMIN_PASSWORD=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c16)
EOF
chmod 600 /opt/weblate_data/secret /opt/weblate_data/weblate.env
set -a
source /opt/weblate_data/weblate.env
set +a
$STD /opt/weblate/.venv/bin/weblate migrate --noinput
$STD /opt/weblate/.venv/bin/weblate createadmin --password="${WEBLATE_ADMIN_PASSWORD}"
$STD /opt/weblate/.venv/bin/weblate collectstatic --noinput
msg_ok "Configured Weblate"
msg_info "Configuring Nginx"
cat <<EOF >/etc/nginx/sites-available/weblate
server {
listen 80;
server_name _;
client_max_body_size 1000M;
location = /favicon.ico {
alias /opt/weblate/cache/static/favicon.ico;
expires 30d;
}
location /static/ {
alias /opt/weblate/cache/static/;
expires 30d;
}
location / {
proxy_pass http://127.0.0.1:8888;
proxy_set_header Host \$http_host;
proxy_set_header X-Forwarded-For \$remote_addr;
proxy_set_header X-Forwarded-Proto \$scheme;
proxy_read_timeout 3600;
}
}
EOF
nginx_enable_site "weblate"
msg_ok "Configured Nginx"
msg_info "Creating Services"
cat <<EOF >/etc/systemd/system/weblate.service
[Unit]
Description=Weblate
After=network.target postgresql.service valkey-server.service
[Service]
Type=simple
User=root
WorkingDirectory=/opt/weblate_data
EnvironmentFile=/opt/weblate_data/weblate.env
ExecStart=/opt/weblate/.venv/bin/granian --interface wsgi --host 127.0.0.1 --port 8888 --workers 2 --blocking-threads 8 --backlog 128 --backpressure 16 --runtime-mode mt --workers-max-rss 450 --no-ws weblate.wsgi:application
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
cat <<EOF >/etc/systemd/system/weblate-celery.service
[Unit]
Description=Weblate Celery Worker
After=network.target postgresql.service valkey-server.service
[Service]
Type=simple
User=root
WorkingDirectory=/opt/weblate_data
EnvironmentFile=/opt/weblate_data/weblate.env
ExecStart=/opt/weblate/.venv/bin/celery --app=weblate.utils worker --beat --loglevel=info --queues=celery,notify,memory,translate,backup --prefetch-multiplier=1 --concurrency=2
Restart=on-failure
RestartSec=10
[Install]
WantedBy=multi-user.target
EOF
systemctl enable -q --now weblate weblate-celery
msg_ok "Created Services"
motd_ssh
customize
cleanup_lxc

View File

@@ -24,7 +24,8 @@ setup_deb_based() {
$STD netfilter-persistent reload
msg_ok "Installed WireGuard"
read -r -p "${TAB3}Would you like to add WGDashboard? <y/N> " prompt
prompt="${var_wireguard_wgdashboard:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to add WGDashboard? <y/N> " prompt
if [[ "${prompt,,}" =~ ^(y|yes)$ ]]; then
git clone -q https://github.com/WGDashboard/WGDashboard.git /etc/wgdashboard
@@ -109,8 +110,9 @@ EOF
$STD sysctl -p /etc/sysctl.conf
msg_ok "Installed WireGuard"
read -rp "${TAB3}Do you want to install WGDashboard? (y/N): " INSTALL_WGD
if [[ "$INSTALL_WGD" =~ ^[Yy]$ ]]; then
INSTALL_WGD="${var_wireguard_wgdashboard:-}"
[[ -n "$INSTALL_WGD" ]] || read -rp "${TAB3}Do you want to install WGDashboard? (y/N): " INSTALL_WGD
if [[ "${INSTALL_WGD,,}" =~ ^(y|yes)$ ]]; then
msg_info "Installing additional dependencies for WGDashboard"
$STD apk add --no-cache \
python3 \

View File

@@ -20,16 +20,7 @@ $STD apt install -y \
ca-certificates
msg_ok "Installed Dependencies"
msg_warn "WARNING: This script will run an external installer from a third-party source (https://yunohost.org/)."
msg_warn "The following code is NOT maintained or audited by our repository."
msg_warn "If you have any doubts or concerns, please review the installer code before proceeding:"
msg_custom "${TAB3}${GATEWAY}${BGN}${CL}" "\e[1;34m" "→ https://install.yunohost.org"
echo
read -r -p "${TAB3}Do you want to continue? [y/N]: " CONFIRM
if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
msg_error "Aborted by user. No changes have been made."
exit 10
fi
confirm_external_installer "https://yunohost.org/" "https://install.yunohost.org"
msg_info "Installing YunoHost (Patience)"
touch /etc/.pve-ignore.resolv.conf

View File

@@ -13,16 +13,7 @@ setting_up_container
network_check
update_os
msg_warn "WARNING: This script will run an external installer from a third-party source (https://install.zerotier.com)."
msg_warn "The following code is NOT maintained or audited by our repository."
msg_warn "If you have any doubts or concerns, please review the installer code before proceeding:"
msg_custom "${TAB3}${GATEWAY}${BGN}${CL}" "\e[1;34m" "→ https://install.zerotier.com"
echo
read -r -p "${TAB3}Do you want to continue? [y/N]: " CONFIRM
if [[ ! $CONFIRM =~ ^([yY][eE][sS]|[yY])$ ]]; then
msg_error "Aborted by user. No changes have been made."
exit 10
fi
confirm_external_installer "https://install.zerotier.com" "https://install.zerotier.com"
msg_info "Setting up Zerotier-One"
curl -fsSL https://raw.githubusercontent.com/zerotier/ZeroTierOne/main/doc/contact%40zerotier.com.gpg | gpg --import >/dev/null 2>&1

View File

@@ -96,6 +96,27 @@ if [[ -f "$LEGACY_DB" || -f "$LEGACY_BIN" && ! -f "$CONFIG_PATH" ]]; then
fi
fi
# v2 rejects v1 config keys and imports the BoltDB on its first start
migrate_v1_config() {
local dir="/usr/local/community-scripts" db=0
[[ -s "$dir/database.db" && ! -s "$dir/filebrowser.sqlite" ]] && db=1
((db)) || grep -qE 'conditionals:|indexingIntervalMinutes:' "$CONFIG_PATH" || return 0
cp "$CONFIG_PATH" "${CONFIG_PATH}.v1.bak"
((db)) && mv "$dir/database.db" "$dir/database.db.old"
awk -v db="$db" '
{ match($0, /^ */); ind = RLENGTH }
/^[^ #]/ { top = $1 }
cond && ind > ci { print substr($0, 3); next }
{ cond = 0 }
/^[[:space:]]*conditionals:[[:space:]]*$/ { cond = 1; ci = ind; next }
/^[[:space:]]*indexingIntervalMinutes:/ { next }
top == "server:" && /^ port:/ { port = $2; next }
{ print }
/^server:/ && db { print " database:"; print " migrateFrom: \"database.db.old\"" }
END { if (port != "") { print "http:"; print " port: " port } }
' "${CONFIG_PATH}.v1.bak" >"$CONFIG_PATH"
}
# Existing installation
if [[ -f "$INSTALL_PATH" ]]; then
msg_warn "${APP} is already installed."
@@ -126,6 +147,7 @@ if [[ -f "$INSTALL_PATH" ]]; then
mv -f /usr/local/bin/filebrowser-quantum "$INSTALL_PATH"
if [[ -f "$CONFIG_PATH" ]]; then
sed -i '/^\s*disableIndexing:/d' "$CONFIG_PATH"
migrate_v1_config
fi
if [[ "$OS" == "Debian" ]]; then
systemctl restart filebrowser.service
@@ -173,22 +195,21 @@ read -r noauth_prompt
# === YAML CONFIG GENERATION ===
if [[ "${noauth_prompt,,}" =~ ^(y|yes)$ ]]; then
cat <<EOF >"$CONFIG_PATH"
server:
http:
port: $PORT
server:
sources:
- path: "$SRC_DIR"
name: "RootFS"
config:
denyByDefault: false
indexingIntervalMinutes: 240
conditionals:
rules:
- neverWatchPath: "/proc"
- neverWatchPath: "/sys"
- neverWatchPath: "/dev"
- neverWatchPath: "/run"
- neverWatchPath: "/tmp"
- neverWatchPath: "/lost+found"
rules:
- neverWatchPath: "/proc"
- neverWatchPath: "/sys"
- neverWatchPath: "/dev"
- neverWatchPath: "/run"
- neverWatchPath: "/tmp"
- neverWatchPath: "/lost+found"
auth:
methods:
noauth: true
@@ -196,22 +217,21 @@ EOF
msg_ok "Configured with no authentication"
else
cat <<EOF >"$CONFIG_PATH"
server:
http:
port: $PORT
server:
sources:
- path: "$SRC_DIR"
name: "RootFS"
config:
denyByDefault: false
indexingIntervalMinutes: 240
conditionals:
rules:
- neverWatchPath: "/proc"
- neverWatchPath: "/sys"
- neverWatchPath: "/dev"
- neverWatchPath: "/run"
- neverWatchPath: "/tmp"
- neverWatchPath: "/lost+found"
rules:
- neverWatchPath: "/proc"
- neverWatchPath: "/sys"
- neverWatchPath: "/dev"
- neverWatchPath: "/run"
- neverWatchPath: "/tmp"
- neverWatchPath: "/lost+found"
auth:
adminUsername: admin
adminPassword: community-scripts.org