Compare commits

...

5 Commits

Author SHA1 Message Date
community-scripts-pr-app[bot]
691a8461f2 Update CHANGELOG.md (#17866)
Some checks are pending
Create Changelog Pull Request / update-changelog-pull-request (push) Waiting to run
Set state to is_deleted in pocketbase / delete-pocketbase-entry (push) Waiting to run
Sync ct/install to Incus / dispatch (push) Waiting to run
Update script timestamp on .sh changes / update-script-timestamp (push) Waiting to run
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 14:16:28 +00:00
CanbiZ (MickLesk)
e0f72e3428 Immich: build libvips with JPEG 2000 support (#17864)
Only the libopenjp2-7 runtime was installed, so meson found no OpenJPEG
and libvips came out without jp2kload. Immich lists .jp2 as supported
and the upstream image builds against libopenjp2-7-dev. Install the
headers, and rebuild libvips on update when it lacks jp2kload, the way
ImageMagick is rebuilt when its LibRaw define is missing.
2026-10-11 16:16:06 +02:00
community-scripts-pr-app[bot]
57316cd66b Update CHANGELOG.md (#17865)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 14:15:13 +00:00
CanbiZ (MickLesk)
192834716e RustDesk Server: run the official server, make the web UI optional (#17854)
* RustDesk Server: run the official server, make the web UI optional

lejianwen/rustdesk-server has had no commit since 2025-09-01 and is 45
commits behind upstream, missing the UDP reflection/amplification and
mio security fixes. hbbs, hbbr and utils now come from
rustdesk/rustdesk-server; the packages and units are the same, so
existing installs upgrade in place and keep their keys.

lejianwen/rustdesk-api is unmaintained as well and becomes an opt-in
prompt. When chosen it is configured with this server's IP and key
instead of its 192.168.1.66 defaults, and Debian gets an admin password
like Alpine did. ~/rustdesk.creds now always holds the server key, and
the API is only updated where it is installed.

* RustDesk Server: answer the web UI prompt with var_rustdesk_api

yes or no skips the question, so unattended installs can choose; unset still asks.

* RustDesk Server: write the creds file with heredocs

Matches how the other install scripts write their creds; the file is unchanged.
2026-10-11 16:14:47 +02:00
CanbiZ (MickLesk)
3845cf97f7 Caddy: install the .deb from GitHub instead of the Cloudsmith repo (#17862)
* Caddy: install the .deb from GitHub instead of the Cloudsmith repo

Cloudsmith answered 402 Payment Required for two days once Caddy's
bandwidth quota ran out, and upstream expects it to happen again
(caddyserver/dist#142). Each GitHub release carries the identical
package (same SHA256), so Debian installs it from there now. The update
drops the Cloudsmith source, seeds ~/.caddy from the installed package
so nothing is reinstalled, and keeps a customised Caddyfile.

* Remove outdated comment from caddy.sh

---------

Co-authored-by: Tobias <96661824+CrazyWolf13@users.noreply.github.com>
2026-10-11 16:14:44 +02:00
7 changed files with 150 additions and 115 deletions

View File

@@ -572,6 +572,7 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
- #### 🐞 Bug Fixes
- Immich: build libvips with JPEG 2000 support [@MickLesk](https://github.com/MickLesk) ([#17864](https://github.com/community-scripts/ProxmoxVE/pull/17864))
- hermesagent: match the relaunched root gateway regardless of interpreter [@MickLesk](https://github.com/MickLesk) ([#17847](https://github.com/community-scripts/ProxmoxVE/pull/17847))
- Radicale: install the bcrypt and argon2 extras [@MickLesk](https://github.com/MickLesk) ([#17813](https://github.com/community-scripts/ProxmoxVE/pull/17813))
- fix(zigbee2mqtt): preserve backup stream and prevent filename collisions [@petermnt](https://github.com/petermnt) ([#17751](https://github.com/community-scripts/ProxmoxVE/pull/17751))
@@ -582,6 +583,11 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
- QoL: Confirm third-party installers through confirm_external_installer [@MickLesk](https://github.com/MickLesk) ([#17857](https://github.com/community-scripts/ProxmoxVE/pull/17857))
- docker: take the lxcfs toggle, TCP socket and Compose choice from app variables [@MickLesk](https://github.com/MickLesk) ([#17850](https://github.com/community-scripts/ProxmoxVE/pull/17850))
- #### 🔧 Refactor
- RustDesk Server: run the official server, make the web UI optional [@MickLesk](https://github.com/MickLesk) ([#17854](https://github.com/community-scripts/ProxmoxVE/pull/17854))
- Caddy: install the .deb from GitHub instead of the Cloudsmith repo [@MickLesk](https://github.com/MickLesk) ([#17862](https://github.com/community-scripts/ProxmoxVE/pull/17862))
### 💾 Core
- Add confirm_external_installer [@MickLesk](https://github.com/MickLesk) ([core#130](https://github.com/community-scripts/core/pull/130))

View File

@@ -38,11 +38,18 @@ update_deb_based() {
exit
fi
cleanup_old_repo_files "caddy"
msg_info "Updating Caddy LXC"
apt_update_safe
$STD apt upgrade -y
msg_ok "Updated Caddy LXC"
[[ -f ~/.caddy ]] || dpkg-query -W -f='${Version}' caddy >~/.caddy 2>/dev/null || true
if check_for_gh_release "caddy" "caddyserver/caddy"; then
DPKG_FORCE_CONFOLD=1 fetch_and_deploy_gh_release "caddy" "caddyserver/caddy" "binary" "latest" "/opt/caddy" "caddy_*_linux_$(arch_resolve).deb"
systemctl restart caddy
fi
if command -v xcaddy >/dev/null 2>&1; then
if check_for_gh_release "xcaddy" "caddyserver/xcaddy"; then
setup_go

View File

@@ -106,7 +106,7 @@ EOF
libraries=("libjxl" "jpegli" "libheif" "libraw" "imagemagick" "libvips")
cd "$BASE_DIR"
msg_warn "Checking for updates to custom image-processing libraries (recompile time: 2-15min per library)"
ensure_dependencies liblcms2-dev libjpeg62-turbo-dev libspng-dev libexif-dev
ensure_dependencies liblcms2-dev libjpeg62-turbo-dev libspng-dev libexif-dev libopenjp2-7-dev
$STD git pull
for library in "${libraries[@]}"; do
compile_"$library"
@@ -565,7 +565,8 @@ function compile_imagemagick() {
function compile_libvips() {
SOURCE=$SOURCE_DIR/libvips
LIBVIPS_REVISION="$(jq -cr '.revision' "$BASE_DIR"/server/sources/libvips.json)"
if [[ "$LIBVIPS_REVISION" != "$(grep 'libvips' ~/.immich_library_revisions | awk '{print $2}')" ]]; then
if [[ "$LIBVIPS_REVISION" != "$(grep 'libvips' ~/.immich_library_revisions | awk '{print $2}')" ]] ||
[[ "$(vips -l foreign 2>/dev/null)" != *jp2kload* ]]; then
msg_info "Recompiling libvips"
[[ -d "$SOURCE" ]] && rm -rf "$SOURCE"
$STD git clone https://github.com/libvips/libvips.git "$SOURCE"

View File

@@ -11,6 +11,7 @@ var_tags="${var_tags:-remote-desktop}"
var_cpu="${var_cpu:-1}"
var_arm64="${var_arm64:-yes}"
var_unprivileged="${var_unprivileged:-1}"
export var_rustdesk_api="${var_rustdesk_api:-}"
if [[ -z "${var_os:-}" ]] && command -v pveversion >/dev/null 2>&1; then
var_os=$(msg_menu "Choose the container OS" \
"debian" "Debian 13" \
@@ -38,25 +39,32 @@ update_deb_based() {
exit
fi
if check_for_gh_release "rustdesk-hbbs" "lejianwen/rustdesk-server"; then
msg_info "Stopping Service"
systemctl stop rustdesk-hbbr
systemctl stop rustdesk-hbbs
if [[ -f /lib/systemd/system/rustdesk-api.service ]]; then
systemctl stop rustdesk-api
fi
msg_ok "Stopped Service"
if check_for_gh_release "rustdesk-hbbs" "rustdesk/rustdesk-server"; then
msg_info "Stopping RustDesk Server"
systemctl stop rustdesk-hbbr rustdesk-hbbs
msg_ok "Stopped RustDesk Server"
fetch_and_deploy_gh_release "rustdesk-hbbr" "rustdesk/rustdesk-server" "binary" "latest" "/opt/rustdesk" "rustdesk-server-hbbr*$(arch_resolve).deb"
fetch_and_deploy_gh_release "rustdesk-hbbs" "rustdesk/rustdesk-server" "binary" "latest" "/opt/rustdesk" "rustdesk-server-hbbs*$(arch_resolve).deb"
fetch_and_deploy_gh_release "rustdesk-utils" "rustdesk/rustdesk-server" "binary" "latest" "/opt/rustdesk" "rustdesk-server-utils*$(arch_resolve).deb"
msg_info "Starting RustDesk Server"
systemctl start rustdesk-hbbs rustdesk-hbbr
msg_ok "Started RustDesk Server"
msg_ok "Updated RustDesk Server"
fi
if [[ -f /lib/systemd/system/rustdesk-api.service ]] && check_for_gh_release "rustdesk-api" "lejianwen/rustdesk-api"; then
msg_info "Stopping RustDesk API"
systemctl stop rustdesk-api
msg_ok "Stopped RustDesk API"
fetch_and_deploy_gh_release "rustdesk-hbbr" "lejianwen/rustdesk-server" "binary" "latest" "/opt/rustdesk" "rustdesk-server-hbbr*$(arch_resolve).deb"
fetch_and_deploy_gh_release "rustdesk-hbbs" "lejianwen/rustdesk-server" "binary" "latest" "/opt/rustdesk" "rustdesk-server-hbbs*$(arch_resolve).deb"
fetch_and_deploy_gh_release "rustdesk-utils" "lejianwen/rustdesk-server" "binary" "latest" "/opt/rustdesk" "rustdesk-server-utils*$(arch_resolve).deb"
fetch_and_deploy_gh_release "rustdesk-api" "lejianwen/rustdesk-api" "binary" "latest" "/opt/rustdesk" "rustdesk-api-server*$(arch_resolve).deb"
msg_info "Starting services"
systemctl start -q rustdesk-*
msg_ok "Services started"
msg_ok "Updated successfully!"
msg_info "Starting RustDesk API"
systemctl start rustdesk-api
msg_ok "Started RustDesk API"
msg_ok "Updated RustDesk API"
fi
}
@@ -66,21 +74,26 @@ update_alpine() {
exit
fi
if check_for_gh_release "rustdesk-server" "lejianwen/rustdesk-server"; then
msg_info "Updating Alpine Packages"
$STD apk -U upgrade
msg_ok "Updated Alpine Packages"
if check_for_gh_release "rustdesk-server" "rustdesk/rustdesk-server"; then
msg_info "Stopping RustDesk Server"
$STD apk -U upgrade
$STD service rustdesk-server-hbbs stop
$STD service rustdesk-server-hbbr stop
msg_ok "Stopped RustDesk Server"
fetch_and_deploy_gh_release "rustdesk-server" "lejianwen/rustdesk-server" "prebuild" "latest" "/opt/rustdesk-server" "rustdesk-server-linux-$(arch_resolve "amd64" "arm64v8").zip"
fetch_and_deploy_gh_release "rustdesk-server" "rustdesk/rustdesk-server" "prebuild" "latest" "/opt/rustdesk-server" "rustdesk-server-linux-$(arch_resolve "amd64" "arm64v8").zip"
msg_info "Starting RustDesk Server"
$STD service rustdesk-server-hbbs start
$STD service rustdesk-server-hbbr start
msg_ok "Started RustDesk Server"
msg_ok "Updated RustDesk Server"
fi
if check_for_gh_release "rustdesk-api" "lejianwen/rustdesk-api"; then
if [[ -x /opt/rustdesk-api/apimain ]] && check_for_gh_release "rustdesk-api" "lejianwen/rustdesk-api"; then
msg_info "Stopping RustDesk API"
$STD service rustdesk-api stop
msg_ok "Stopped RustDesk API"
@@ -90,8 +103,8 @@ update_alpine() {
msg_info "Starting RustDesk API"
$STD service rustdesk-api start
msg_ok "Started RustDesk API"
msg_ok "Updated RustDesk API"
fi
msg_ok "Updated successfully!"
}
function update_script() {
@@ -107,5 +120,7 @@ description
msg_ok "Completed successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}:21114${CL}"
echo -e "${INFO}${YW}Set this as ID server in the RustDesk client, the key is in ~/rustdesk.creds:${CL}"
echo -e "${GATEWAY}${BGN}${IP}${CL}"
echo -e "${INFO}${YW}Web UI, if selected during setup:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}:21114/_admin/${CL}"

View File

@@ -14,21 +14,8 @@ network_check
update_os
setup_deb_based() {
msg_info "Installing Dependencies"
$STD apt install -y \
debian-keyring \
debian-archive-keyring \
apt-transport-https
msg_ok "Installed Dependencies"
msg_info "Installing Caddy"
setup_deb822_repo \
"caddy" \
"https://dl.cloudsmith.io/public/caddy/stable/gpg.key" \
"https://dl.cloudsmith.io/public/caddy/stable/deb/debian" \
"any-version"
$STD apt install -y caddy
msg_ok "Installed Caddy"
fetch_and_deploy_gh_release "caddy" "caddyserver/caddy" "binary" "latest" "/opt/caddy" "caddy_*_linux_$(arch_resolve).deb"
systemctl enable -q --now caddy
prompt="${var_caddy_xcaddy:-}"
[[ -n "$prompt" ]] || read -r -p "${TAB3}Would you like to install xCaddy Addon? <y/N> " prompt

View File

@@ -84,6 +84,7 @@ $STD apt install --no-install-recommends -y \
liblqr-1-0 \
libltdl7 \
libopenjp2-7 \
libopenjp2-7-dev \
meson \
ninja-build \
pkg-config \

View File

@@ -13,108 +13,126 @@ setting_up_container
network_check
update_os
if [[ -n "${var_rustdesk_api:-}" ]]; then
prompt="$var_rustdesk_api"
else
read -r -p "${TAB3}Would you like to add the RustDesk API web UI (lejianwen/rustdesk-api, unmaintained since 09/2025)? <y/N> " prompt
fi
INSTALL_API=0
[[ "${prompt,,}" =~ ^(y|yes|true)$ ]] && INSTALL_API=1
API_PASS="$(random_password 16)"
# rustdesk-api hands these to clients; its shipped defaults point at 192.168.1.66
api_env() {
printf '%s\n' \
"RUSTDESK_API_RUSTDESK_ID_SERVER=${LOCAL_IP}:21116" \
"RUSTDESK_API_RUSTDESK_RELAY_SERVER=${LOCAL_IP}:21117" \
"RUSTDESK_API_RUSTDESK_API_SERVER=http://${LOCAL_IP}:21114" \
"RUSTDESK_API_RUSTDESK_KEY_FILE=$1"
}
# hbbs creates its key pair in its working directory on first start
write_creds() {
local key_file="$1"
for _ in $(seq 1 30); do
[[ -s "$key_file" ]] && break
sleep 1
done
if [[ ! -s "$key_file" ]]; then
msg_error "hbbs did not create ${key_file}"
exit 1
fi
cat <<EOF >~/rustdesk.creds
RustDesk Server
ID Server: ${LOCAL_IP}
Key: $(<"$key_file")
EOF
if ((INSTALL_API)); then
cat <<EOF >>~/rustdesk.creds
RustDesk API Web UI: http://${LOCAL_IP}:21114/_admin/
Username: admin
Password: ${API_PASS}
EOF
fi
}
setup_deb_based() {
fetch_and_deploy_gh_release "rustdesk-hbbr" "lejianwen/rustdesk-server" "binary" "latest" "/opt/rustdesk" "rustdesk-server-hbbr*$(arch_resolve).deb"
fetch_and_deploy_gh_release "rustdesk-hbbs" "lejianwen/rustdesk-server" "binary" "latest" "/opt/rustdesk" "rustdesk-server-hbbs*$(arch_resolve).deb"
fetch_and_deploy_gh_release "rustdesk-utils" "lejianwen/rustdesk-server" "binary" "latest" "/opt/rustdesk" "rustdesk-server-utils*$(arch_resolve).deb"
fetch_and_deploy_gh_release "rustdesk-api" "lejianwen/rustdesk-api" "binary" "latest" "/opt/rustdesk" "rustdesk-api-server*$(arch_resolve).deb"
systemctl enable -q --now rustdesk-hbbr
systemctl enable -q --now rustdesk-hbbs
systemctl enable -q --now rustdesk-api
fetch_and_deploy_gh_release "rustdesk-hbbr" "rustdesk/rustdesk-server" "binary" "latest" "/opt/rustdesk" "rustdesk-server-hbbr*$(arch_resolve).deb"
fetch_and_deploy_gh_release "rustdesk-hbbs" "rustdesk/rustdesk-server" "binary" "latest" "/opt/rustdesk" "rustdesk-server-hbbs*$(arch_resolve).deb"
fetch_and_deploy_gh_release "rustdesk-utils" "rustdesk/rustdesk-server" "binary" "latest" "/opt/rustdesk" "rustdesk-server-utils*$(arch_resolve).deb"
systemctl enable -q --now rustdesk-hbbs rustdesk-hbbr
write_creds /var/lib/rustdesk-server/id_ed25519.pub
if ((INSTALL_API)); then
fetch_and_deploy_gh_release "rustdesk-api" "lejianwen/rustdesk-api" "binary" "latest" "/opt/rustdesk" "rustdesk-api-server*$(arch_resolve).deb"
msg_info "Configuring RustDesk API"
mkdir -p /etc/systemd/system/rustdesk-api.service.d
{
echo "[Service]"
api_env /var/lib/rustdesk-server/id_ed25519.pub | sed 's/^/Environment=/'
} >/etc/systemd/system/rustdesk-api.service.d/override.conf
systemctl daemon-reload
systemctl stop rustdesk-api
cd /var/lib/rustdesk-api
$STD rustdesk-api reset-admin-pwd "$API_PASS"
systemctl enable -q --now rustdesk-api
msg_ok "Configured RustDesk API"
fi
}
setup_alpine() {
fetch_and_deploy_gh_release "rustdesk-server" "lejianwen/rustdesk-server" "prebuild" "latest" "/opt/rustdesk-server" "rustdesk-server-linux-$(arch_resolve "amd64" "arm64v8").zip"
fetch_and_deploy_gh_release "rustdesk-server" "rustdesk/rustdesk-server" "prebuild" "latest" "/opt/rustdesk-server" "rustdesk-server-linux-$(arch_resolve "amd64" "arm64v8").zip"
msg_info "Configuring RustDesk Server"
mkdir -p /root/.config/rustdesk
cd /opt/rustdesk-server
./rustdesk-utils genkeypair >/tmp/rustdesk_keys.txt
grep "Public Key" /tmp/rustdesk_keys.txt | awk '{print $3}' >/root/.config/rustdesk/id_ed25519.pub
grep "Secret Key" /tmp/rustdesk_keys.txt | awk '{print $3}' >/root/.config/rustdesk/id_ed25519
chmod 600 /root/.config/rustdesk/id_ed25519
chmod 644 /root/.config/rustdesk/id_ed25519.pub
rm /tmp/rustdesk_keys.txt
msg_ok "Configured RustDesk Server"
fetch_and_deploy_gh_release "rustdesk-api" "lejianwen/rustdesk-api" "prebuild" "latest" "/opt/rustdesk-api" "linux-$(arch_resolve).tar.gz"
msg_info "Configuring RustDesk API"
cd /opt/rustdesk-api
ADMINPASS=$(head -c 16 /dev/urandom | xxd -p -c 16)
$STD ./apimain reset-admin-pwd "$ADMINPASS"
cat <<EOF >~/rustdesk.creds
RustDesk WebUI
Username: admin
Password: $ADMINPASS
EOF
msg_ok "Configured RustDesk API"
msg_info "Enabling RustDesk Server Services"
cat <<EOF >/etc/init.d/rustdesk-server-hbbs
msg_info "Creating RustDesk Server Services"
for svc in hbbs hbbr; do
cat <<EOF >"/etc/init.d/rustdesk-server-${svc}"
#!/sbin/openrc-run
description="RustDesk HBBS Service"
description="RustDesk ${svc^^} Service"
directory="/opt/rustdesk-server"
command="/opt/rustdesk-server/hbbs"
command_args=""
command="/opt/rustdesk-server/${svc}"
command_background="true"
command_user="root"
pidfile="/var/run/rustdesk-server-hbbs.pid"
output_log="/var/log/rustdesk-hbbs.log"
error_log="/var/log/rustdesk-hbbs.err"
pidfile="/var/run/rustdesk-server-${svc}.pid"
output_log="/var/log/rustdesk-${svc}.log"
error_log="/var/log/rustdesk-${svc}.err"
depend() {
use net
}
EOF
chmod +x "/etc/init.d/rustdesk-server-${svc}"
$STD rc-update add "rustdesk-server-${svc}" default
$STD service "rustdesk-server-${svc}" start
done
msg_ok "Created RustDesk Server Services"
write_creds /opt/rustdesk-server/id_ed25519.pub
cat <<EOF >/etc/init.d/rustdesk-server-hbbr
#!/sbin/openrc-run
description="RustDesk HBBR Service"
directory="/opt/rustdesk-server"
command="/opt/rustdesk-server/hbbr"
command_args=""
command_background="true"
command_user="root"
pidfile="/var/run/rustdesk-server-hbbr.pid"
output_log="/var/log/rustdesk-hbbr.log"
error_log="/var/log/rustdesk-hbbr.err"
depend() {
use net
}
EOF
cat <<EOF >/etc/init.d/rustdesk-api
if ((INSTALL_API)); then
fetch_and_deploy_gh_release "rustdesk-api" "lejianwen/rustdesk-api" "prebuild" "latest" "/opt/rustdesk-api" "linux-$(arch_resolve).tar.gz"
msg_info "Configuring RustDesk API"
api_env /opt/rustdesk-server/id_ed25519.pub | sed 's/^/export /' >/etc/conf.d/rustdesk-api
cd /opt/rustdesk-api
$STD ./apimain reset-admin-pwd "$API_PASS"
cat <<EOF >/etc/init.d/rustdesk-api
#!/sbin/openrc-run
description="RustDesk API Service"
directory="/opt/rustdesk-api"
command="/opt/rustdesk-api/apimain"
command_args=""
command_background="true"
command_user="root"
pidfile="/var/run/rustdesk-api.pid"
output_log="/var/log/rustdesk-api.log"
error_log="/var/log/rustdesk-api.err"
depend() {
use net
after rustdesk-server-hbbs
}
EOF
chmod +x /etc/init.d/rustdesk-server-hbbs
chmod +x /etc/init.d/rustdesk-server-hbbr
chmod +x /etc/init.d/rustdesk-api
$STD rc-update add rustdesk-server-hbbs default
$STD rc-update add rustdesk-server-hbbr default
$STD rc-update add rustdesk-api default
msg_ok "Enabled RustDesk Server Services"
msg_info "Starting RustDesk Server"
$STD service rustdesk-server-hbbs start
$STD service rustdesk-server-hbbr start
$STD service rustdesk-api start
msg_ok "Started RustDesk Server"
chmod +x /etc/init.d/rustdesk-api
$STD rc-update add rustdesk-api default
$STD service rustdesk-api start
msg_ok "Configured RustDesk API"
fi
}
run_os_setup