mirror of
https://github.com/community-scripts/ProxmoxVE.git
synced 2026-10-10 18:09:56 -04:00
Compare commits
12 Commits
2026-10-09
...
github-act
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
1f8de9a202 | ||
|
|
0a8c97c765 | ||
|
|
1bcd22137e | ||
|
|
1bc4191951 | ||
|
|
d1bad678e9 | ||
|
|
2d12d0e0b1 | ||
|
|
cd06638952 | ||
|
|
65ee461b14 | ||
|
|
9fdbb10a45 | ||
|
|
e274342a54 | ||
|
|
05fd051fb6 | ||
|
|
c5c107c374 |
16
CHANGELOG.md
16
CHANGELOG.md
@@ -559,6 +559,22 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
|
||||
|
||||
</details>
|
||||
|
||||
## 2026-10-10
|
||||
|
||||
### 🆕 New Scripts
|
||||
|
||||
- Weblate ([#17837](https://github.com/community-scripts/ProxmoxVE/pull/17837))
|
||||
- CertMate ([#17803](https://github.com/community-scripts/ProxmoxVE/pull/17803))
|
||||
- AnythingLLM ([#17802](https://github.com/community-scripts/ProxmoxVE/pull/17802))
|
||||
|
||||
### 🚀 Updated Scripts
|
||||
|
||||
- #### 🐞 Bug Fixes
|
||||
|
||||
- update endurain repo from codeberg to gh [@johanngrobe](https://github.com/johanngrobe) ([#17831](https://github.com/community-scripts/ProxmoxVE/pull/17831))
|
||||
- Immich: download countryInfo.txt into the geodata directory on update [@claytonfaria](https://github.com/claytonfaria) ([#17823](https://github.com/community-scripts/ProxmoxVE/pull/17823))
|
||||
- paperclip: keep root and skip /opt/paperclip-data chown when PAPERCLIP_HOME is custom [@austinpilz](https://github.com/austinpilz) ([#17825](https://github.com/community-scripts/ProxmoxVE/pull/17825))
|
||||
|
||||
## 2026-10-09
|
||||
|
||||
### 🆕 New Scripts
|
||||
|
||||
78
ct/anythingllm.sh
Normal file
78
ct/anythingllm.sh
Normal file
@@ -0,0 +1,78 @@
|
||||
#!/usr/bin/env bash
|
||||
# Engine comes from community-scripts/core; this repo only ships the scripts.
|
||||
# A local core checkout wins (COMMUNITY_SCRIPTS_CORE_DIR, else a sibling ../core),
|
||||
# so a fork or branch of core can be tested without editing this file.
|
||||
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
|
||||
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
|
||||
# Copyright (c) 2021-2026 community-scripts ORG
|
||||
# Author: MickLesk (CanbiZ)
|
||||
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||
# Source: https://github.com/Mintplex-Labs/anything-llm
|
||||
|
||||
APP="AnythingLLM"
|
||||
var_tags="${var_tags:-ai;rag}"
|
||||
var_cpu="${var_cpu:-4}"
|
||||
var_ram="${var_ram:-6144}"
|
||||
var_disk="${var_disk:-20}"
|
||||
var_os="${var_os:-debian}"
|
||||
var_version="${var_version:-13}"
|
||||
var_gpu="${var_gpu:-yes}"
|
||||
#var_arm64="${var_arm64:-no}" # unset = ask the user; set yes/no only when verified
|
||||
var_unprivileged="${var_unprivileged:-1}"
|
||||
|
||||
header_info "$APP"
|
||||
variables
|
||||
color
|
||||
catch_errors
|
||||
|
||||
function update_script() {
|
||||
header_info
|
||||
check_container_storage
|
||||
check_container_resources
|
||||
|
||||
if [[ ! -d /opt/anythingllm ]]; then
|
||||
msg_error "No ${APP} Installation Found!"
|
||||
exit
|
||||
fi
|
||||
|
||||
if check_for_gh_release "anythingllm" "Mintplex-Labs/anything-llm"; then
|
||||
msg_info "Stopping Services"
|
||||
systemctl stop anythingllm anythingllm-collector
|
||||
msg_ok "Stopped Services"
|
||||
|
||||
create_backup /opt/anythingllm/server/.env /opt/anythingllm/collector/.env /opt/anythingllm/frontend/.env
|
||||
|
||||
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "anythingllm" "Mintplex-Labs/anything-llm" "tarball"
|
||||
|
||||
restore_backup
|
||||
|
||||
msg_info "Building AnythingLLM (Patience)"
|
||||
cd /opt/anythingllm
|
||||
export PUPPETEER_SKIP_DOWNLOAD=true
|
||||
export NODE_OPTIONS="--max-old-space-size=3072"
|
||||
$STD yarn setup
|
||||
cd /opt/anythingllm/frontend
|
||||
$STD yarn build
|
||||
rm -rf /opt/anythingllm/server/public
|
||||
cp -R /opt/anythingllm/frontend/dist /opt/anythingllm/server/public
|
||||
cd /opt/anythingllm/server
|
||||
$STD npx prisma generate --schema=./prisma/schema.prisma
|
||||
$STD npx prisma migrate deploy --schema=./prisma/schema.prisma
|
||||
msg_ok "Built AnythingLLM"
|
||||
|
||||
msg_info "Starting Services"
|
||||
systemctl start anythingllm anythingllm-collector
|
||||
msg_ok "Started Services"
|
||||
msg_ok "Updated successfully!"
|
||||
fi
|
||||
exit
|
||||
}
|
||||
|
||||
start
|
||||
build_container
|
||||
description
|
||||
|
||||
msg_ok "Completed Successfully!\n"
|
||||
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
|
||||
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
|
||||
echo -e "${GATEWAY}${BGN}http://${IP}:3001${CL}"
|
||||
65
ct/certmate.sh
Normal file
65
ct/certmate.sh
Normal file
@@ -0,0 +1,65 @@
|
||||
#!/usr/bin/env bash
|
||||
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
|
||||
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
|
||||
# Copyright (c) 2021-2026 community-scripts ORG
|
||||
# Author: fabriziosalmi
|
||||
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||
# Source: https://github.com/fabriziosalmi/certmate
|
||||
|
||||
APP="CertMate"
|
||||
var_tags="${var_tags:-ssl;certificates;acme}"
|
||||
var_cpu="${var_cpu:-2}"
|
||||
var_ram="${var_ram:-2048}"
|
||||
var_disk="${var_disk:-8}"
|
||||
var_os="${var_os:-debian}"
|
||||
var_version="${var_version:-13}"
|
||||
#var_arm64="${var_arm64:-no}" # unset = ask the user; set yes/no only when verified
|
||||
var_unprivileged="${var_unprivileged:-1}"
|
||||
|
||||
header_info "$APP"
|
||||
variables
|
||||
color
|
||||
catch_errors
|
||||
|
||||
function update_script() {
|
||||
header_info
|
||||
check_container_storage
|
||||
check_container_resources
|
||||
|
||||
if [[ ! -d /opt/certmate ]]; then
|
||||
msg_error "No ${APP} Installation Found!"
|
||||
exit
|
||||
fi
|
||||
|
||||
if check_for_gh_release "certmate" "fabriziosalmi/certmate"; then
|
||||
msg_info "Stopping CertMate"
|
||||
systemctl stop certmate
|
||||
msg_ok "Stopped CertMate"
|
||||
|
||||
PYTHON_VERSION="3.12" setup_uv
|
||||
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "certmate" "fabriziosalmi/certmate" "tarball"
|
||||
|
||||
msg_info "Installing CertMate Dependencies"
|
||||
cd /opt/certmate
|
||||
$STD uv venv --python 3.12 /opt/certmate/.venv
|
||||
$STD uv pip sync --python /opt/certmate/.venv/bin/python requirements.lock
|
||||
$STD /opt/certmate/.venv/bin/certbot --version
|
||||
msg_ok "Installed CertMate Dependencies"
|
||||
|
||||
msg_info "Starting CertMate"
|
||||
systemctl start certmate
|
||||
msg_ok "Started CertMate"
|
||||
msg_ok "Updated successfully!"
|
||||
fi
|
||||
exit
|
||||
}
|
||||
|
||||
start
|
||||
build_container
|
||||
description
|
||||
|
||||
msg_ok "Completed Successfully!\n"
|
||||
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
|
||||
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
|
||||
echo -e "${GATEWAY}${BGN}http://${IP}:8000${CL}"
|
||||
echo -e "${INFO}${YW}The first page creates the admin account and asks for the API token: grep API_BEARER_TOKEN /opt/certmate_data/.env${CL}"
|
||||
@@ -30,14 +30,14 @@ function update_script() {
|
||||
msg_error "No ${APP} installation found!"
|
||||
exit 233
|
||||
fi
|
||||
if check_for_codeberg_release "endurain" "endurain-project/endurain"; then
|
||||
if check_for_gh_release "endurain" "endurain-project/endurain"; then
|
||||
msg_info "Stopping Service"
|
||||
systemctl stop endurain
|
||||
msg_ok "Stopped Service"
|
||||
|
||||
NODE_VERSION="24" setup_nodejs
|
||||
create_backup /opt/endurain/.env /opt/endurain/frontend/dist/env.js
|
||||
CLEAN_INSTALL=1 fetch_and_deploy_codeberg_release "endurain" "endurain-project/endurain" "tarball" "latest" "/opt/endurain"
|
||||
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "endurain" "endurain-project/endurain"
|
||||
|
||||
msg_info "Updating Endurain Frontend"
|
||||
cd /opt/endurain
|
||||
|
||||
@@ -329,7 +329,7 @@ EOF
|
||||
grep -rl /usr/src | xargs -n1 sed -i "s|\/usr/src|$INSTALL_DIR|g"
|
||||
grep -rlE "'/build'" | xargs -n1 sed -i "s|'/build'|'$APP_DIR'|g"
|
||||
sed -i "s@\"/cache\"@\"$INSTALL_DIR/cache\"@g" "$ML_DIR"/immich_ml/config.py
|
||||
[[ ! -f "$GEO_DIR/countryInfo.txt" ]] && curl_with_retry "https://download.geonames.org/export/dump/countryInfo.txt" "countryInfo.txt"
|
||||
[[ ! -f "$GEO_DIR/countryInfo.txt" ]] && curl_with_retry "https://download.geonames.org/export/dump/countryInfo.txt" "$GEO_DIR/countryInfo.txt"
|
||||
ln -s "${UPLOAD_DIR:-/opt/immich/upload}" "$APP_DIR"/upload
|
||||
ln -s "${UPLOAD_DIR:-/opt/immich/upload}" "$ML_DIR"/upload
|
||||
ln -sfn "$GEO_DIR" "$APP_DIR/geodata"
|
||||
|
||||
@@ -63,7 +63,13 @@ function update_script() {
|
||||
|
||||
# Claude Code refuses --dangerously-skip-permissions as root; migrate existing installs to a dedicated user
|
||||
PAPERCLIP_USER=$(sed -n 's/^User=//p' /etc/systemd/system/paperclip.service)
|
||||
if [[ -z "$PAPERCLIP_USER" || "$PAPERCLIP_USER" == "root" ]]; then
|
||||
PAPERCLIP_HOME=$(sed -n 's/^PAPERCLIP_HOME=//p' /opt/paperclip-ai/.env)
|
||||
PAPERCLIP_HOME="${PAPERCLIP_HOME:-/opt/paperclip-data}"
|
||||
if [[ -z "$PAPERCLIP_USER" || "$PAPERCLIP_USER" == "root" ]] && [[ "$PAPERCLIP_HOME" != "/opt/paperclip-data" ]]; then
|
||||
# A custom data dir (e.g. an NFS bind mount) may only be reachable by root; don't move the service off root
|
||||
msg_warn "PAPERCLIP_HOME is ${PAPERCLIP_HOME}; keeping the service user as root"
|
||||
PAPERCLIP_USER=root
|
||||
elif [[ -z "$PAPERCLIP_USER" || "$PAPERCLIP_USER" == "root" ]]; then
|
||||
PAPERCLIP_USER="${var_paperclip_user:-paperclip}"
|
||||
if [[ "$PAPERCLIP_USER" == "root" || ! "$PAPERCLIP_USER" =~ ^[a-z_][a-z0-9_-]{0,31}$ ]]; then
|
||||
msg_error "Invalid var_paperclip_user '${PAPERCLIP_USER}' (must be a non-root lowercase Linux username)"
|
||||
@@ -85,7 +91,10 @@ function update_script() {
|
||||
fi
|
||||
PAPERCLIP_USER_HOME=$(getent passwd "$PAPERCLIP_USER" | cut -d: -f6)
|
||||
chmod 600 /opt/paperclip-ai/.env
|
||||
chown -R "${PAPERCLIP_USER}:${PAPERCLIP_USER}" /opt/paperclip-ai /opt/paperclip-data "$PAPERCLIP_USER_HOME"
|
||||
chown -R "${PAPERCLIP_USER}:${PAPERCLIP_USER}" /opt/paperclip-ai "$PAPERCLIP_USER_HOME"
|
||||
if [[ "$PAPERCLIP_HOME" == "/opt/paperclip-data" && -d /opt/paperclip-data ]]; then
|
||||
chown -R "${PAPERCLIP_USER}:${PAPERCLIP_USER}" /opt/paperclip-data
|
||||
fi
|
||||
|
||||
msg_info "Running Database Migrations"
|
||||
set -a && source /opt/paperclip-ai/.env && set +a
|
||||
|
||||
67
ct/weblate.sh
Normal file
67
ct/weblate.sh
Normal file
@@ -0,0 +1,67 @@
|
||||
#!/usr/bin/env bash
|
||||
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
|
||||
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
|
||||
# Copyright (c) 2021-2026 community-scripts ORG
|
||||
# Author: MickLesk (CanbiZ)
|
||||
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||
# Source: https://github.com/WeblateOrg/weblate
|
||||
|
||||
APP="Weblate"
|
||||
var_tags="${var_tags:-translation;localization}"
|
||||
var_cpu="${var_cpu:-2}"
|
||||
var_ram="${var_ram:-3072}"
|
||||
var_disk="${var_disk:-10}"
|
||||
var_os="${var_os:-debian}"
|
||||
var_version="${var_version:-13}"
|
||||
var_arm64="${var_arm64:-yes}"
|
||||
var_unprivileged="${var_unprivileged:-1}"
|
||||
|
||||
header_info "$APP"
|
||||
variables
|
||||
color
|
||||
catch_errors
|
||||
|
||||
function update_script() {
|
||||
header_info
|
||||
check_container_storage
|
||||
check_container_resources
|
||||
|
||||
if [[ ! -d /opt/weblate ]]; then
|
||||
msg_error "No ${APP} Installation Found!"
|
||||
exit
|
||||
fi
|
||||
|
||||
if check_for_gh_release "weblate" "WeblateOrg/weblate"; then
|
||||
msg_info "Stopping Weblate"
|
||||
systemctl stop weblate weblate-celery
|
||||
msg_ok "Stopped Weblate"
|
||||
|
||||
PYTHON_VERSION="3.14" setup_uv
|
||||
USE_ORIGINAL_FILENAME=true fetch_and_deploy_gh_release "weblate" "WeblateOrg/weblate" "singlefile" "latest" "/opt/weblate" "weblate-*-py3-none-any.whl"
|
||||
|
||||
msg_info "Updating Weblate"
|
||||
$STD uv pip install --python /opt/weblate/.venv/bin/python --compile-bytecode /opt/weblate/weblate-*.whl "weblate[all,wsgi]"
|
||||
rm -f /opt/weblate/weblate-*.whl
|
||||
set -a
|
||||
source /opt/weblate_data/weblate.env
|
||||
set +a
|
||||
$STD /opt/weblate/.venv/bin/weblate migrate --noinput
|
||||
$STD /opt/weblate/.venv/bin/weblate collectstatic --noinput
|
||||
msg_ok "Updated Weblate"
|
||||
|
||||
msg_info "Starting Weblate"
|
||||
systemctl start weblate-celery weblate
|
||||
msg_ok "Started Weblate"
|
||||
msg_ok "Updated successfully!"
|
||||
fi
|
||||
exit
|
||||
}
|
||||
|
||||
start
|
||||
build_container
|
||||
description
|
||||
|
||||
msg_ok "Completed Successfully!\n"
|
||||
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
|
||||
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
|
||||
echo -e "${GATEWAY}${BGN}http://${IP}${CL}"
|
||||
107
install/anythingllm-install.sh
Normal file
107
install/anythingllm-install.sh
Normal file
@@ -0,0 +1,107 @@
|
||||
#!/usr/bin/env bash
|
||||
|
||||
# Copyright (c) 2021-2026 community-scripts ORG
|
||||
# Author: MickLesk (CanbiZ)
|
||||
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||
# Source: https://github.com/Mintplex-Labs/anything-llm
|
||||
|
||||
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
|
||||
color
|
||||
verb_ip6
|
||||
catch_errors
|
||||
setting_up_container
|
||||
network_check
|
||||
update_os
|
||||
|
||||
msg_info "Installing Dependencies"
|
||||
$STD apt install -y \
|
||||
build-essential \
|
||||
python3-dev \
|
||||
libgomp1 \
|
||||
git \
|
||||
chromium
|
||||
msg_ok "Installed Dependencies"
|
||||
|
||||
NODE_VERSION="22" NODE_MODULE="yarn" setup_nodejs
|
||||
|
||||
fetch_and_deploy_gh_release "anythingllm" "Mintplex-Labs/anything-llm" "tarball"
|
||||
|
||||
msg_info "Configuring AnythingLLM"
|
||||
mkdir -p /opt/anythingllm_data/storage
|
||||
cp -RTn /opt/anythingllm/server/storage /opt/anythingllm_data/storage 2>/dev/null || true
|
||||
rm -rf /opt/anythingllm/server/storage
|
||||
ln -sfn /opt/anythingllm_data/storage /opt/anythingllm/server/storage
|
||||
cat <<EOF >/opt/anythingllm/server/.env
|
||||
SERVER_PORT=3001
|
||||
STORAGE_DIR="/opt/anythingllm/server/storage"
|
||||
JWT_SECRET="$(openssl rand -hex 32)"
|
||||
SIG_KEY="$(openssl rand -hex 32)"
|
||||
SIG_SALT="$(openssl rand -hex 32)"
|
||||
VECTOR_DB="lancedb"
|
||||
EOF
|
||||
cat <<EOF >/opt/anythingllm/collector/.env
|
||||
STORAGE_DIR="/opt/anythingllm/server/storage"
|
||||
EOF
|
||||
cat <<EOF >/opt/anythingllm/frontend/.env
|
||||
VITE_API_BASE='/api'
|
||||
EOF
|
||||
msg_ok "Configured AnythingLLM"
|
||||
|
||||
msg_info "Building AnythingLLM (Patience)"
|
||||
cd /opt/anythingllm
|
||||
export PUPPETEER_SKIP_DOWNLOAD=true
|
||||
export NODE_OPTIONS="--max-old-space-size=3072"
|
||||
$STD yarn setup
|
||||
cd /opt/anythingllm/frontend
|
||||
$STD yarn build
|
||||
cp -R /opt/anythingllm/frontend/dist /opt/anythingllm/server/public
|
||||
cd /opt/anythingllm/server
|
||||
$STD npx prisma generate --schema=./prisma/schema.prisma
|
||||
$STD npx prisma migrate deploy --schema=./prisma/schema.prisma
|
||||
msg_ok "Built AnythingLLM"
|
||||
|
||||
msg_info "Creating Services"
|
||||
cat <<EOF >/etc/systemd/system/anythingllm.service
|
||||
[Unit]
|
||||
Description=AnythingLLM Server
|
||||
Wants=network-online.target
|
||||
After=network-online.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=root
|
||||
WorkingDirectory=/opt/anythingllm/server
|
||||
Environment=NODE_ENV=production
|
||||
ExecStart=/usr/bin/node index.js
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
EOF
|
||||
|
||||
cat <<EOF >/etc/systemd/system/anythingllm-collector.service
|
||||
[Unit]
|
||||
Description=AnythingLLM Collector
|
||||
Wants=network-online.target
|
||||
After=network-online.target anythingllm.service
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=root
|
||||
WorkingDirectory=/opt/anythingllm/collector
|
||||
Environment=NODE_ENV=production
|
||||
Environment=PUPPETEER_EXECUTABLE_PATH=/usr/bin/chromium
|
||||
ExecStart=/usr/bin/node index.js
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
EOF
|
||||
systemctl enable -q --now anythingllm anythingllm-collector
|
||||
msg_ok "Created Services"
|
||||
|
||||
motd_ssh
|
||||
customize
|
||||
cleanup_lxc
|
||||
69
install/certmate-install.sh
Normal file
69
install/certmate-install.sh
Normal file
@@ -0,0 +1,69 @@
|
||||
#!/usr/bin/env bash
|
||||
|
||||
# Copyright (c) 2021-2026 community-scripts ORG
|
||||
# Author: fabriziosalmi
|
||||
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||
# Source: https://github.com/fabriziosalmi/certmate
|
||||
|
||||
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
|
||||
color
|
||||
verb_ip6
|
||||
catch_errors
|
||||
setting_up_container
|
||||
network_check
|
||||
update_os
|
||||
|
||||
PYTHON_VERSION="3.12" setup_uv
|
||||
fetch_and_deploy_gh_release "certmate" "fabriziosalmi/certmate" "tarball"
|
||||
|
||||
msg_info "Installing CertMate Dependencies"
|
||||
cd /opt/certmate
|
||||
$STD uv venv --python 3.12 /opt/certmate/.venv
|
||||
# requirements.lock is the fully pinned set the official image is built from
|
||||
$STD uv pip sync --python /opt/certmate/.venv/bin/python requirements.lock
|
||||
$STD /opt/certmate/.venv/bin/certbot --version
|
||||
msg_ok "Installed CertMate Dependencies"
|
||||
|
||||
msg_info "Configuring CertMate"
|
||||
mkdir -p /opt/certmate_data/{certificates,data,backups,logs}
|
||||
cat <<EOF >/opt/certmate_data/.env
|
||||
API_BEARER_TOKEN=$(openssl rand -hex 32)
|
||||
SECRET_KEY=$(openssl rand -hex 32)
|
||||
CERTMATE_BACKUP_PASSPHRASE=$(openssl rand -hex 32)
|
||||
BEHIND_PROXY=false
|
||||
EOF
|
||||
chmod 600 /opt/certmate_data/.env
|
||||
msg_ok "Configured CertMate"
|
||||
|
||||
msg_info "Creating Service"
|
||||
cat <<EOF >/etc/systemd/system/certmate.service
|
||||
[Unit]
|
||||
Description=CertMate SSL Certificate Manager
|
||||
After=network-online.target
|
||||
Wants=network-online.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=root
|
||||
WorkingDirectory=/opt/certmate
|
||||
Environment=PATH=/opt/certmate/.venv/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
|
||||
Environment=CERTMATE_CERT_DIR=/opt/certmate_data/certificates
|
||||
Environment=CERTMATE_DATA_DIR=/opt/certmate_data/data
|
||||
Environment=CERTMATE_BACKUP_DIR=/opt/certmate_data/backups
|
||||
Environment=CERTMATE_LOGS_DIR=/opt/certmate_data/logs
|
||||
Environment=ACME_CHALLENGES_DIR=/opt/certmate_data/data/acme-challenges
|
||||
EnvironmentFile=/opt/certmate_data/.env
|
||||
# One worker: the renewal scheduler, sessions and rate limits live in-process
|
||||
ExecStart=/opt/certmate/.venv/bin/gunicorn --bind 0.0.0.0:8000 --workers 1 --threads 8 --timeout 300 --no-control-socket app:app
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
EOF
|
||||
systemctl enable -q --now certmate
|
||||
msg_ok "Created Service"
|
||||
|
||||
motd_ssh
|
||||
customize
|
||||
cleanup_lxc
|
||||
@@ -21,7 +21,7 @@ PYTHON_VERSION="3.13" setup_uv
|
||||
NODE_VERSION="24" setup_nodejs
|
||||
PG_VERSION="17" PG_MODULES="postgis" setup_postgresql
|
||||
PG_DB_NAME="enduraindb" PG_DB_USER="endurain" setup_postgresql_db
|
||||
fetch_and_deploy_codeberg_release "endurain" "endurain-project/endurain" "tarball" "latest" "/opt/endurain"
|
||||
fetch_and_deploy_gh_release "endurain" "endurain-project/endurain"
|
||||
|
||||
msg_info "Setting up Endurain"
|
||||
cd /opt/endurain
|
||||
|
||||
144
install/weblate-install.sh
Normal file
144
install/weblate-install.sh
Normal file
@@ -0,0 +1,144 @@
|
||||
#!/usr/bin/env bash
|
||||
|
||||
# Copyright (c) 2021-2026 community-scripts ORG
|
||||
# Author: MickLesk (CanbiZ)
|
||||
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||
# Source: https://github.com/WeblateOrg/weblate
|
||||
|
||||
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
|
||||
color
|
||||
verb_ip6
|
||||
catch_errors
|
||||
setting_up_container
|
||||
network_check
|
||||
update_os
|
||||
|
||||
msg_info "Installing Dependencies"
|
||||
$STD apt install -y \
|
||||
build-essential \
|
||||
pkg-config \
|
||||
libacl1-dev \
|
||||
liblz4-dev \
|
||||
libzstd-dev \
|
||||
libxxhash-dev \
|
||||
libssl-dev \
|
||||
libldap2-dev \
|
||||
libsasl2-dev \
|
||||
git \
|
||||
gettext \
|
||||
nginx \
|
||||
valkey-server
|
||||
msg_ok "Installed Dependencies"
|
||||
|
||||
PG_VERSION="17" setup_postgresql
|
||||
PG_DB_NAME="weblate" PG_DB_USER="weblate" setup_postgresql_db
|
||||
PYTHON_VERSION="3.14" setup_uv
|
||||
USE_ORIGINAL_FILENAME=true fetch_and_deploy_gh_release "weblate" "WeblateOrg/weblate" "singlefile" "latest" "/opt/weblate" "weblate-*-py3-none-any.whl"
|
||||
|
||||
msg_info "Installing Weblate"
|
||||
$STD uv venv --python 3.14 /opt/weblate/.venv
|
||||
$STD uv pip install --python /opt/weblate/.venv/bin/python --compile-bytecode /opt/weblate/weblate-*.whl "weblate[all,wsgi]"
|
||||
rm -f /opt/weblate/weblate-*.whl
|
||||
msg_ok "Installed Weblate"
|
||||
|
||||
msg_info "Configuring Weblate"
|
||||
mkdir -p /opt/weblate_data/python/customize /app
|
||||
# weblate.settings_docker is upstream's env-driven settings; it reads the secret and
|
||||
# settings-override.py from /app/data and loads the "customize" app from DATA_DIR/python
|
||||
ln -sfn /opt/weblate_data /app/data
|
||||
touch /opt/weblate_data/python/customize/{__init__,models}.py
|
||||
/opt/weblate/.venv/bin/weblate-generate-secret-key >/opt/weblate_data/secret
|
||||
cat <<EOF >/opt/weblate_data/weblate.env
|
||||
DJANGO_SETTINGS_MODULE=weblate.settings_docker
|
||||
PYTHONPATH=/opt/weblate_data/python
|
||||
WEBLATE_SITE_DOMAIN=${LOCAL_IP}
|
||||
WEBLATE_DATA_DIR=/opt/weblate_data
|
||||
WEBLATE_CACHE_DIR=/opt/weblate/cache
|
||||
WEBLATE_IP_PROXY_HEADER=HTTP_X_FORWARDED_FOR
|
||||
POSTGRES_HOST=127.0.0.1
|
||||
POSTGRES_DB=weblate
|
||||
POSTGRES_USER=weblate
|
||||
POSTGRES_PASSWORD=${PG_DB_PASS}
|
||||
REDIS_HOST=127.0.0.1
|
||||
# Password set for the "admin" account at install; Weblate does not read it
|
||||
WEBLATE_ADMIN_PASSWORD=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c16)
|
||||
EOF
|
||||
chmod 600 /opt/weblate_data/secret /opt/weblate_data/weblate.env
|
||||
set -a
|
||||
source /opt/weblate_data/weblate.env
|
||||
set +a
|
||||
$STD /opt/weblate/.venv/bin/weblate migrate --noinput
|
||||
$STD /opt/weblate/.venv/bin/weblate createadmin --password="${WEBLATE_ADMIN_PASSWORD}"
|
||||
$STD /opt/weblate/.venv/bin/weblate collectstatic --noinput
|
||||
msg_ok "Configured Weblate"
|
||||
|
||||
msg_info "Configuring Nginx"
|
||||
cat <<EOF >/etc/nginx/sites-available/weblate
|
||||
server {
|
||||
listen 80;
|
||||
server_name _;
|
||||
client_max_body_size 1000M;
|
||||
|
||||
location = /favicon.ico {
|
||||
alias /opt/weblate/cache/static/favicon.ico;
|
||||
expires 30d;
|
||||
}
|
||||
|
||||
location /static/ {
|
||||
alias /opt/weblate/cache/static/;
|
||||
expires 30d;
|
||||
}
|
||||
|
||||
location / {
|
||||
proxy_pass http://127.0.0.1:8888;
|
||||
proxy_set_header Host \$http_host;
|
||||
proxy_set_header X-Forwarded-For \$remote_addr;
|
||||
proxy_set_header X-Forwarded-Proto \$scheme;
|
||||
proxy_read_timeout 3600;
|
||||
}
|
||||
}
|
||||
EOF
|
||||
nginx_enable_site "weblate"
|
||||
msg_ok "Configured Nginx"
|
||||
|
||||
msg_info "Creating Services"
|
||||
cat <<EOF >/etc/systemd/system/weblate.service
|
||||
[Unit]
|
||||
Description=Weblate
|
||||
After=network.target postgresql.service valkey-server.service
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=root
|
||||
WorkingDirectory=/opt/weblate_data
|
||||
EnvironmentFile=/opt/weblate_data/weblate.env
|
||||
ExecStart=/opt/weblate/.venv/bin/granian --interface wsgi --host 127.0.0.1 --port 8888 --workers 2 --blocking-threads 8 --backlog 128 --backpressure 16 --runtime-mode mt --workers-max-rss 450 --no-ws weblate.wsgi:application
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
EOF
|
||||
cat <<EOF >/etc/systemd/system/weblate-celery.service
|
||||
[Unit]
|
||||
Description=Weblate Celery Worker
|
||||
After=network.target postgresql.service valkey-server.service
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=root
|
||||
WorkingDirectory=/opt/weblate_data
|
||||
EnvironmentFile=/opt/weblate_data/weblate.env
|
||||
ExecStart=/opt/weblate/.venv/bin/celery --app=weblate.utils worker --beat --loglevel=info --queues=celery,notify,memory,translate,backup --prefetch-multiplier=1 --concurrency=2
|
||||
Restart=on-failure
|
||||
RestartSec=10
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
EOF
|
||||
systemctl enable -q --now weblate weblate-celery
|
||||
msg_ok "Created Services"
|
||||
|
||||
motd_ssh
|
||||
customize
|
||||
cleanup_lxc
|
||||
Reference in New Issue
Block a user