mirror of
https://github.com/community-scripts/ProxmoxVE.git
synced 2026-10-10 10:00:07 -04:00
Compare commits
1 Commits
github-act
...
fix/paperl
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
a7da6dfdda |
28
CHANGELOG.md
28
CHANGELOG.md
@@ -559,20 +559,6 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
|
||||
|
||||
</details>
|
||||
|
||||
## 2026-10-10
|
||||
|
||||
### 🆕 New Scripts
|
||||
|
||||
- CertMate ([#17803](https://github.com/community-scripts/ProxmoxVE/pull/17803))
|
||||
- AnythingLLM ([#17802](https://github.com/community-scripts/ProxmoxVE/pull/17802))
|
||||
|
||||
### 🚀 Updated Scripts
|
||||
|
||||
- #### 🐞 Bug Fixes
|
||||
|
||||
- Immich: download countryInfo.txt into the geodata directory on update [@claytonfaria](https://github.com/claytonfaria) ([#17823](https://github.com/community-scripts/ProxmoxVE/pull/17823))
|
||||
- paperclip: keep root and skip /opt/paperclip-data chown when PAPERCLIP_HOME is custom [@austinpilz](https://github.com/austinpilz) ([#17825](https://github.com/community-scripts/ProxmoxVE/pull/17825))
|
||||
|
||||
## 2026-10-09
|
||||
|
||||
### 🆕 New Scripts
|
||||
@@ -583,24 +569,10 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
|
||||
|
||||
### 🚀 Updated Scripts
|
||||
|
||||
- #### 🐞 Bug Fixes
|
||||
|
||||
- OpenCloud: fix Collabora embedding with Collabora 26.04.4 [@SimKaiLong](https://github.com/SimKaiLong) ([#17810](https://github.com/community-scripts/ProxmoxVE/pull/17810))
|
||||
|
||||
- #### 🔧 Refactor
|
||||
|
||||
- Immich: survive an interrupted update and a failing ML build [@MickLesk](https://github.com/MickLesk) ([#17798](https://github.com/community-scripts/ProxmoxVE/pull/17798))
|
||||
|
||||
### 💾 Core
|
||||
|
||||
- check_for_release: compare against the release marked as latest [@MickLesk](https://github.com/MickLesk) ([core#125](https://github.com/community-scripts/core/pull/125))
|
||||
|
||||
### 🧰 Tools
|
||||
|
||||
- #### ✨ New Features
|
||||
|
||||
- FileBrowser Quantum: migrate the config and database to v2 [@MickLesk](https://github.com/MickLesk) ([#17815](https://github.com/community-scripts/ProxmoxVE/pull/17815))
|
||||
|
||||
## 2026-10-08
|
||||
|
||||
### 🆕 New Scripts
|
||||
|
||||
@@ -1,78 +0,0 @@
|
||||
#!/usr/bin/env bash
|
||||
# Engine comes from community-scripts/core; this repo only ships the scripts.
|
||||
# A local core checkout wins (COMMUNITY_SCRIPTS_CORE_DIR, else a sibling ../core),
|
||||
# so a fork or branch of core can be tested without editing this file.
|
||||
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
|
||||
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
|
||||
# Copyright (c) 2021-2026 community-scripts ORG
|
||||
# Author: MickLesk (CanbiZ)
|
||||
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||
# Source: https://github.com/Mintplex-Labs/anything-llm
|
||||
|
||||
APP="AnythingLLM"
|
||||
var_tags="${var_tags:-ai;rag}"
|
||||
var_cpu="${var_cpu:-4}"
|
||||
var_ram="${var_ram:-6144}"
|
||||
var_disk="${var_disk:-20}"
|
||||
var_os="${var_os:-debian}"
|
||||
var_version="${var_version:-13}"
|
||||
var_gpu="${var_gpu:-yes}"
|
||||
#var_arm64="${var_arm64:-no}" # unset = ask the user; set yes/no only when verified
|
||||
var_unprivileged="${var_unprivileged:-1}"
|
||||
|
||||
header_info "$APP"
|
||||
variables
|
||||
color
|
||||
catch_errors
|
||||
|
||||
function update_script() {
|
||||
header_info
|
||||
check_container_storage
|
||||
check_container_resources
|
||||
|
||||
if [[ ! -d /opt/anythingllm ]]; then
|
||||
msg_error "No ${APP} Installation Found!"
|
||||
exit
|
||||
fi
|
||||
|
||||
if check_for_gh_release "anythingllm" "Mintplex-Labs/anything-llm"; then
|
||||
msg_info "Stopping Services"
|
||||
systemctl stop anythingllm anythingllm-collector
|
||||
msg_ok "Stopped Services"
|
||||
|
||||
create_backup /opt/anythingllm/server/.env /opt/anythingllm/collector/.env /opt/anythingllm/frontend/.env
|
||||
|
||||
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "anythingllm" "Mintplex-Labs/anything-llm" "tarball"
|
||||
|
||||
restore_backup
|
||||
|
||||
msg_info "Building AnythingLLM (Patience)"
|
||||
cd /opt/anythingllm
|
||||
export PUPPETEER_SKIP_DOWNLOAD=true
|
||||
export NODE_OPTIONS="--max-old-space-size=3072"
|
||||
$STD yarn setup
|
||||
cd /opt/anythingllm/frontend
|
||||
$STD yarn build
|
||||
rm -rf /opt/anythingllm/server/public
|
||||
cp -R /opt/anythingllm/frontend/dist /opt/anythingllm/server/public
|
||||
cd /opt/anythingllm/server
|
||||
$STD npx prisma generate --schema=./prisma/schema.prisma
|
||||
$STD npx prisma migrate deploy --schema=./prisma/schema.prisma
|
||||
msg_ok "Built AnythingLLM"
|
||||
|
||||
msg_info "Starting Services"
|
||||
systemctl start anythingllm anythingllm-collector
|
||||
msg_ok "Started Services"
|
||||
msg_ok "Updated successfully!"
|
||||
fi
|
||||
exit
|
||||
}
|
||||
|
||||
start
|
||||
build_container
|
||||
description
|
||||
|
||||
msg_ok "Completed Successfully!\n"
|
||||
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
|
||||
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
|
||||
echo -e "${GATEWAY}${BGN}http://${IP}:3001${CL}"
|
||||
@@ -1,65 +0,0 @@
|
||||
#!/usr/bin/env bash
|
||||
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
|
||||
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
|
||||
# Copyright (c) 2021-2026 community-scripts ORG
|
||||
# Author: fabriziosalmi
|
||||
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||
# Source: https://github.com/fabriziosalmi/certmate
|
||||
|
||||
APP="CertMate"
|
||||
var_tags="${var_tags:-ssl;certificates;acme}"
|
||||
var_cpu="${var_cpu:-2}"
|
||||
var_ram="${var_ram:-2048}"
|
||||
var_disk="${var_disk:-8}"
|
||||
var_os="${var_os:-debian}"
|
||||
var_version="${var_version:-13}"
|
||||
#var_arm64="${var_arm64:-no}" # unset = ask the user; set yes/no only when verified
|
||||
var_unprivileged="${var_unprivileged:-1}"
|
||||
|
||||
header_info "$APP"
|
||||
variables
|
||||
color
|
||||
catch_errors
|
||||
|
||||
function update_script() {
|
||||
header_info
|
||||
check_container_storage
|
||||
check_container_resources
|
||||
|
||||
if [[ ! -d /opt/certmate ]]; then
|
||||
msg_error "No ${APP} Installation Found!"
|
||||
exit
|
||||
fi
|
||||
|
||||
if check_for_gh_release "certmate" "fabriziosalmi/certmate"; then
|
||||
msg_info "Stopping CertMate"
|
||||
systemctl stop certmate
|
||||
msg_ok "Stopped CertMate"
|
||||
|
||||
PYTHON_VERSION="3.12" setup_uv
|
||||
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "certmate" "fabriziosalmi/certmate" "tarball"
|
||||
|
||||
msg_info "Installing CertMate Dependencies"
|
||||
cd /opt/certmate
|
||||
$STD uv venv --python 3.12 /opt/certmate/.venv
|
||||
$STD uv pip sync --python /opt/certmate/.venv/bin/python requirements.lock
|
||||
$STD /opt/certmate/.venv/bin/certbot --version
|
||||
msg_ok "Installed CertMate Dependencies"
|
||||
|
||||
msg_info "Starting CertMate"
|
||||
systemctl start certmate
|
||||
msg_ok "Started CertMate"
|
||||
msg_ok "Updated successfully!"
|
||||
fi
|
||||
exit
|
||||
}
|
||||
|
||||
start
|
||||
build_container
|
||||
description
|
||||
|
||||
msg_ok "Completed Successfully!\n"
|
||||
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
|
||||
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
|
||||
echo -e "${GATEWAY}${BGN}http://${IP}:8000${CL}"
|
||||
echo -e "${INFO}${YW}The first page creates the admin account and asks for the API token: grep API_BEARER_TOKEN /opt/certmate_data/.env${CL}"
|
||||
@@ -329,7 +329,7 @@ EOF
|
||||
grep -rl /usr/src | xargs -n1 sed -i "s|\/usr/src|$INSTALL_DIR|g"
|
||||
grep -rlE "'/build'" | xargs -n1 sed -i "s|'/build'|'$APP_DIR'|g"
|
||||
sed -i "s@\"/cache\"@\"$INSTALL_DIR/cache\"@g" "$ML_DIR"/immich_ml/config.py
|
||||
[[ ! -f "$GEO_DIR/countryInfo.txt" ]] && curl_with_retry "https://download.geonames.org/export/dump/countryInfo.txt" "$GEO_DIR/countryInfo.txt"
|
||||
[[ ! -f "$GEO_DIR/countryInfo.txt" ]] && curl_with_retry "https://download.geonames.org/export/dump/countryInfo.txt" "countryInfo.txt"
|
||||
ln -s "${UPLOAD_DIR:-/opt/immich/upload}" "$APP_DIR"/upload
|
||||
ln -s "${UPLOAD_DIR:-/opt/immich/upload}" "$ML_DIR"/upload
|
||||
ln -sfn "$GEO_DIR" "$APP_DIR/geodata"
|
||||
|
||||
@@ -31,15 +31,6 @@ function update_script() {
|
||||
exit
|
||||
fi
|
||||
|
||||
# Collabora 26.04.4 ignores frame-ancestors in content_security_policy; outside the release
|
||||
# check so installs already on the current release get it too
|
||||
if [[ -f /etc/coolwsd/coolwsd.xml ]] && ! grep -q '<frame_ancestors[^>]*>[^<[:space:]]' /etc/coolwsd/coolwsd.xml; then
|
||||
msg_info "Allowing OpenCloud to embed Collabora"
|
||||
$STD sudo -u cool coolconfig set net.frame_ancestors "$(sed -n 's/^OC_URL=//p' /etc/opencloud/opencloud.env)"
|
||||
systemctl restart coolwsd
|
||||
msg_ok "Allowed OpenCloud to embed Collabora"
|
||||
fi
|
||||
|
||||
RELEASE="v8.1.0"
|
||||
if check_for_gh_release "OpenCloud" "opencloud-eu/opencloud" "${RELEASE}" "each release is tested individually before the version is updated. Please do not open issues for this"; then
|
||||
OLD_VERSION="$(cat ~/.opencloud 2>/dev/null)"
|
||||
|
||||
@@ -63,13 +63,7 @@ function update_script() {
|
||||
|
||||
# Claude Code refuses --dangerously-skip-permissions as root; migrate existing installs to a dedicated user
|
||||
PAPERCLIP_USER=$(sed -n 's/^User=//p' /etc/systemd/system/paperclip.service)
|
||||
PAPERCLIP_HOME=$(sed -n 's/^PAPERCLIP_HOME=//p' /opt/paperclip-ai/.env)
|
||||
PAPERCLIP_HOME="${PAPERCLIP_HOME:-/opt/paperclip-data}"
|
||||
if [[ -z "$PAPERCLIP_USER" || "$PAPERCLIP_USER" == "root" ]] && [[ "$PAPERCLIP_HOME" != "/opt/paperclip-data" ]]; then
|
||||
# A custom data dir (e.g. an NFS bind mount) may only be reachable by root; don't move the service off root
|
||||
msg_warn "PAPERCLIP_HOME is ${PAPERCLIP_HOME}; keeping the service user as root"
|
||||
PAPERCLIP_USER=root
|
||||
elif [[ -z "$PAPERCLIP_USER" || "$PAPERCLIP_USER" == "root" ]]; then
|
||||
if [[ -z "$PAPERCLIP_USER" || "$PAPERCLIP_USER" == "root" ]]; then
|
||||
PAPERCLIP_USER="${var_paperclip_user:-paperclip}"
|
||||
if [[ "$PAPERCLIP_USER" == "root" || ! "$PAPERCLIP_USER" =~ ^[a-z_][a-z0-9_-]{0,31}$ ]]; then
|
||||
msg_error "Invalid var_paperclip_user '${PAPERCLIP_USER}' (must be a non-root lowercase Linux username)"
|
||||
@@ -91,10 +85,7 @@ function update_script() {
|
||||
fi
|
||||
PAPERCLIP_USER_HOME=$(getent passwd "$PAPERCLIP_USER" | cut -d: -f6)
|
||||
chmod 600 /opt/paperclip-ai/.env
|
||||
chown -R "${PAPERCLIP_USER}:${PAPERCLIP_USER}" /opt/paperclip-ai "$PAPERCLIP_USER_HOME"
|
||||
if [[ "$PAPERCLIP_HOME" == "/opt/paperclip-data" && -d /opt/paperclip-data ]]; then
|
||||
chown -R "${PAPERCLIP_USER}:${PAPERCLIP_USER}" /opt/paperclip-data
|
||||
fi
|
||||
chown -R "${PAPERCLIP_USER}:${PAPERCLIP_USER}" /opt/paperclip-ai /opt/paperclip-data "$PAPERCLIP_USER_HOME"
|
||||
|
||||
msg_info "Running Database Migrations"
|
||||
set -a && source /opt/paperclip-ai/.env && set +a
|
||||
|
||||
@@ -157,8 +157,6 @@ function update_script() {
|
||||
sed -i '$a\PAPERLESS_ARCHIVE_FILE_GENERATION=never' "$PAPERLESS_CONF"
|
||||
fi
|
||||
fi
|
||||
[[ -n "$(sed -n '/^PAPERLESS_CONSUMER_IGNORE_PATTERNS=/p' "$PAPERLESS_CONF")" ]] &&
|
||||
msg_warn "PAPERLESS_CONSUMER_IGNORE_PATTERNS now uses regex patterns; please verify custom values."
|
||||
[[ -n "$(sed -n '/^PAPERLESS_PRE_CONSUME_SCRIPT=/p;/^PAPERLESS_POST_CONSUME_SCRIPT=/p' "$PAPERLESS_CONF")" ]] &&
|
||||
msg_warn "Pre/post consume scripts no longer receive positional arguments in v3; please verify custom scripts."
|
||||
msg_ok "Migrated Paperless-ngx configuration"
|
||||
@@ -172,7 +170,9 @@ function update_script() {
|
||||
fi
|
||||
for svc in consumer scheduler task-queue webserver; do
|
||||
unit="/etc/systemd/system/paperless-${svc}.service"
|
||||
[[ -f "$unit" ]] && sed -i 's|uv run -- |uv run --no-sync -- |g' "$unit"
|
||||
[[ -f "$unit" ]] || continue
|
||||
sed -i 's|uv run -- |uv run --no-sync -- |g' "$unit"
|
||||
grep -q '^Restart=' "$unit" || sed -i '/^\[Service\]/a Restart=on-failure\nRestartSec=5' "$unit"
|
||||
done
|
||||
$STD systemctl daemon-reload
|
||||
cd /opt/paperless
|
||||
@@ -181,6 +181,34 @@ function update_script() {
|
||||
$STD uv run -- python manage.py migrate
|
||||
msg_ok "Updated Paperless-ngx"
|
||||
|
||||
if ((BRIDGE_UPDATE == 0)); then
|
||||
IGNORE_FIXED="$(
|
||||
/opt/paperless/.venv/bin/python - /opt/paperless/paperless.conf <<'EOF'
|
||||
import json, re, sys
|
||||
key = "PAPERLESS_CONSUMER_IGNORE_PATTERNS="
|
||||
lines = open(sys.argv[1]).read().splitlines(True)
|
||||
|
||||
def is_glob(p):
|
||||
if p.startswith("^") or p.endswith("$"):
|
||||
return False
|
||||
try:
|
||||
return bool(re.search(p, "scan.pdf"))
|
||||
except re.error:
|
||||
return True
|
||||
|
||||
for i, line in enumerate(lines):
|
||||
if line.startswith(key):
|
||||
patterns = json.loads(line[len(key):].strip().strip("'"))
|
||||
fixed = ["^" + re.escape(p).replace(r"\*", ".*").replace(r"\?", ".") + "$" if is_glob(p) else p for p in patterns]
|
||||
if fixed != patterns:
|
||||
lines[i] = key + json.dumps(fixed) + "\n"
|
||||
print(json.dumps(fixed))
|
||||
open(sys.argv[1], "w").writelines(lines)
|
||||
EOF
|
||||
)" || IGNORE_FIXED=""
|
||||
[[ -n "$IGNORE_FIXED" ]] && msg_warn "Converted glob PAPERLESS_CONSUMER_IGNORE_PATTERNS to regex (required since v3): ${IGNORE_FIXED}"
|
||||
fi
|
||||
|
||||
if ((BRIDGE_UPDATE == 0)) && [[ "$PAPERLESS_INSTALLED_VERSION" == "2.20.15" ]]; then
|
||||
$STD apt -y purge libzbar0t64 libzbar0 2>/dev/null || true
|
||||
$STD apt -y autoremove 2>/dev/null || true
|
||||
|
||||
@@ -1,107 +0,0 @@
|
||||
#!/usr/bin/env bash
|
||||
|
||||
# Copyright (c) 2021-2026 community-scripts ORG
|
||||
# Author: MickLesk (CanbiZ)
|
||||
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||
# Source: https://github.com/Mintplex-Labs/anything-llm
|
||||
|
||||
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
|
||||
color
|
||||
verb_ip6
|
||||
catch_errors
|
||||
setting_up_container
|
||||
network_check
|
||||
update_os
|
||||
|
||||
msg_info "Installing Dependencies"
|
||||
$STD apt install -y \
|
||||
build-essential \
|
||||
python3-dev \
|
||||
libgomp1 \
|
||||
git \
|
||||
chromium
|
||||
msg_ok "Installed Dependencies"
|
||||
|
||||
NODE_VERSION="22" NODE_MODULE="yarn" setup_nodejs
|
||||
|
||||
fetch_and_deploy_gh_release "anythingllm" "Mintplex-Labs/anything-llm" "tarball"
|
||||
|
||||
msg_info "Configuring AnythingLLM"
|
||||
mkdir -p /opt/anythingllm_data/storage
|
||||
cp -RTn /opt/anythingllm/server/storage /opt/anythingllm_data/storage 2>/dev/null || true
|
||||
rm -rf /opt/anythingllm/server/storage
|
||||
ln -sfn /opt/anythingllm_data/storage /opt/anythingllm/server/storage
|
||||
cat <<EOF >/opt/anythingllm/server/.env
|
||||
SERVER_PORT=3001
|
||||
STORAGE_DIR="/opt/anythingllm/server/storage"
|
||||
JWT_SECRET="$(openssl rand -hex 32)"
|
||||
SIG_KEY="$(openssl rand -hex 32)"
|
||||
SIG_SALT="$(openssl rand -hex 32)"
|
||||
VECTOR_DB="lancedb"
|
||||
EOF
|
||||
cat <<EOF >/opt/anythingllm/collector/.env
|
||||
STORAGE_DIR="/opt/anythingllm/server/storage"
|
||||
EOF
|
||||
cat <<EOF >/opt/anythingllm/frontend/.env
|
||||
VITE_API_BASE='/api'
|
||||
EOF
|
||||
msg_ok "Configured AnythingLLM"
|
||||
|
||||
msg_info "Building AnythingLLM (Patience)"
|
||||
cd /opt/anythingllm
|
||||
export PUPPETEER_SKIP_DOWNLOAD=true
|
||||
export NODE_OPTIONS="--max-old-space-size=3072"
|
||||
$STD yarn setup
|
||||
cd /opt/anythingllm/frontend
|
||||
$STD yarn build
|
||||
cp -R /opt/anythingllm/frontend/dist /opt/anythingllm/server/public
|
||||
cd /opt/anythingllm/server
|
||||
$STD npx prisma generate --schema=./prisma/schema.prisma
|
||||
$STD npx prisma migrate deploy --schema=./prisma/schema.prisma
|
||||
msg_ok "Built AnythingLLM"
|
||||
|
||||
msg_info "Creating Services"
|
||||
cat <<EOF >/etc/systemd/system/anythingllm.service
|
||||
[Unit]
|
||||
Description=AnythingLLM Server
|
||||
Wants=network-online.target
|
||||
After=network-online.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=root
|
||||
WorkingDirectory=/opt/anythingllm/server
|
||||
Environment=NODE_ENV=production
|
||||
ExecStart=/usr/bin/node index.js
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
EOF
|
||||
|
||||
cat <<EOF >/etc/systemd/system/anythingllm-collector.service
|
||||
[Unit]
|
||||
Description=AnythingLLM Collector
|
||||
Wants=network-online.target
|
||||
After=network-online.target anythingllm.service
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=root
|
||||
WorkingDirectory=/opt/anythingllm/collector
|
||||
Environment=NODE_ENV=production
|
||||
Environment=PUPPETEER_EXECUTABLE_PATH=/usr/bin/chromium
|
||||
ExecStart=/usr/bin/node index.js
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
EOF
|
||||
systemctl enable -q --now anythingllm anythingllm-collector
|
||||
msg_ok "Created Services"
|
||||
|
||||
motd_ssh
|
||||
customize
|
||||
cleanup_lxc
|
||||
@@ -1,69 +0,0 @@
|
||||
#!/usr/bin/env bash
|
||||
|
||||
# Copyright (c) 2021-2026 community-scripts ORG
|
||||
# Author: fabriziosalmi
|
||||
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||
# Source: https://github.com/fabriziosalmi/certmate
|
||||
|
||||
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
|
||||
color
|
||||
verb_ip6
|
||||
catch_errors
|
||||
setting_up_container
|
||||
network_check
|
||||
update_os
|
||||
|
||||
PYTHON_VERSION="3.12" setup_uv
|
||||
fetch_and_deploy_gh_release "certmate" "fabriziosalmi/certmate" "tarball"
|
||||
|
||||
msg_info "Installing CertMate Dependencies"
|
||||
cd /opt/certmate
|
||||
$STD uv venv --python 3.12 /opt/certmate/.venv
|
||||
# requirements.lock is the fully pinned set the official image is built from
|
||||
$STD uv pip sync --python /opt/certmate/.venv/bin/python requirements.lock
|
||||
$STD /opt/certmate/.venv/bin/certbot --version
|
||||
msg_ok "Installed CertMate Dependencies"
|
||||
|
||||
msg_info "Configuring CertMate"
|
||||
mkdir -p /opt/certmate_data/{certificates,data,backups,logs}
|
||||
cat <<EOF >/opt/certmate_data/.env
|
||||
API_BEARER_TOKEN=$(openssl rand -hex 32)
|
||||
SECRET_KEY=$(openssl rand -hex 32)
|
||||
CERTMATE_BACKUP_PASSPHRASE=$(openssl rand -hex 32)
|
||||
BEHIND_PROXY=false
|
||||
EOF
|
||||
chmod 600 /opt/certmate_data/.env
|
||||
msg_ok "Configured CertMate"
|
||||
|
||||
msg_info "Creating Service"
|
||||
cat <<EOF >/etc/systemd/system/certmate.service
|
||||
[Unit]
|
||||
Description=CertMate SSL Certificate Manager
|
||||
After=network-online.target
|
||||
Wants=network-online.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=root
|
||||
WorkingDirectory=/opt/certmate
|
||||
Environment=PATH=/opt/certmate/.venv/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
|
||||
Environment=CERTMATE_CERT_DIR=/opt/certmate_data/certificates
|
||||
Environment=CERTMATE_DATA_DIR=/opt/certmate_data/data
|
||||
Environment=CERTMATE_BACKUP_DIR=/opt/certmate_data/backups
|
||||
Environment=CERTMATE_LOGS_DIR=/opt/certmate_data/logs
|
||||
Environment=ACME_CHALLENGES_DIR=/opt/certmate_data/data/acme-challenges
|
||||
EnvironmentFile=/opt/certmate_data/.env
|
||||
# One worker: the renewal scheduler, sessions and rate limits live in-process
|
||||
ExecStart=/opt/certmate/.venv/bin/gunicorn --bind 0.0.0.0:8000 --workers 1 --threads 8 --timeout 300 --no-control-socket app:app
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
EOF
|
||||
systemctl enable -q --now certmate
|
||||
msg_ok "Created Service"
|
||||
|
||||
motd_ssh
|
||||
customize
|
||||
cleanup_lxc
|
||||
@@ -207,7 +207,7 @@ EOF
|
||||
$STD sudo -u cool coolconfig set ssl.enable false
|
||||
$STD sudo -u cool coolconfig set ssl.termination true
|
||||
$STD sudo -u cool coolconfig set ssl.ssl_verification true
|
||||
$STD sudo -u cool coolconfig set net.frame_ancestors "https://${OPENCLOUD_FQDN}"
|
||||
sed -i "s|-Policy\">|&frame-ancestors https://${OPENCLOUD_FQDN}|" /etc/coolwsd/coolwsd.xml
|
||||
useradd -r -M -s /usr/sbin/nologin opencloud
|
||||
chown -R opencloud:opencloud "$CONFIG_DIR" "$DATA_DIR"
|
||||
sudo -u opencloud opencloud init --config-path "$CONFIG_DIR" --insecure no
|
||||
|
||||
@@ -109,6 +109,8 @@ Requires=redis.service
|
||||
[Service]
|
||||
WorkingDirectory=/opt/paperless/src
|
||||
ExecStart=uv run --no-sync -- celery --app paperless beat --loglevel INFO
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
@@ -123,6 +125,8 @@ After=postgresql.service
|
||||
[Service]
|
||||
WorkingDirectory=/opt/paperless/src
|
||||
ExecStart=uv run --no-sync -- celery --app paperless worker --loglevel INFO
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
@@ -137,6 +141,8 @@ Requires=redis.service
|
||||
WorkingDirectory=/opt/paperless/src
|
||||
ExecStartPre=/bin/sleep 2
|
||||
ExecStart=uv run --no-sync -- python manage.py document_consumer
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
@@ -153,6 +159,8 @@ Requires=redis.service
|
||||
WorkingDirectory=/opt/paperless/src
|
||||
#ExecStartPre=uv run --no-sync -- python manage.py document_index reindex --if-needed --no-progress-bar
|
||||
ExecStart=uv run --no-sync -- granian --interface asginl --ws --loop uvloop "paperless.asgi:application"
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
Environment=GRANIAN_HOST=::
|
||||
Environment=GRANIAN_PORT=8000
|
||||
Environment=GRANIAN_WORKERS=1
|
||||
|
||||
@@ -96,27 +96,6 @@ if [[ -f "$LEGACY_DB" || -f "$LEGACY_BIN" && ! -f "$CONFIG_PATH" ]]; then
|
||||
fi
|
||||
fi
|
||||
|
||||
# v2 rejects v1 config keys and imports the BoltDB on its first start
|
||||
migrate_v1_config() {
|
||||
local dir="/usr/local/community-scripts" db=0
|
||||
[[ -s "$dir/database.db" && ! -s "$dir/filebrowser.sqlite" ]] && db=1
|
||||
((db)) || grep -qE 'conditionals:|indexingIntervalMinutes:' "$CONFIG_PATH" || return 0
|
||||
cp "$CONFIG_PATH" "${CONFIG_PATH}.v1.bak"
|
||||
((db)) && mv "$dir/database.db" "$dir/database.db.old"
|
||||
awk -v db="$db" '
|
||||
{ match($0, /^ */); ind = RLENGTH }
|
||||
/^[^ #]/ { top = $1 }
|
||||
cond && ind > ci { print substr($0, 3); next }
|
||||
{ cond = 0 }
|
||||
/^[[:space:]]*conditionals:[[:space:]]*$/ { cond = 1; ci = ind; next }
|
||||
/^[[:space:]]*indexingIntervalMinutes:/ { next }
|
||||
top == "server:" && /^ port:/ { port = $2; next }
|
||||
{ print }
|
||||
/^server:/ && db { print " database:"; print " migrateFrom: \"database.db.old\"" }
|
||||
END { if (port != "") { print "http:"; print " port: " port } }
|
||||
' "${CONFIG_PATH}.v1.bak" >"$CONFIG_PATH"
|
||||
}
|
||||
|
||||
# Existing installation
|
||||
if [[ -f "$INSTALL_PATH" ]]; then
|
||||
msg_warn "${APP} is already installed."
|
||||
@@ -147,7 +126,6 @@ if [[ -f "$INSTALL_PATH" ]]; then
|
||||
mv -f /usr/local/bin/filebrowser-quantum "$INSTALL_PATH"
|
||||
if [[ -f "$CONFIG_PATH" ]]; then
|
||||
sed -i '/^\s*disableIndexing:/d' "$CONFIG_PATH"
|
||||
migrate_v1_config
|
||||
fi
|
||||
if [[ "$OS" == "Debian" ]]; then
|
||||
systemctl restart filebrowser.service
|
||||
@@ -195,21 +173,22 @@ read -r noauth_prompt
|
||||
# === YAML CONFIG GENERATION ===
|
||||
if [[ "${noauth_prompt,,}" =~ ^(y|yes)$ ]]; then
|
||||
cat <<EOF >"$CONFIG_PATH"
|
||||
http:
|
||||
port: $PORT
|
||||
server:
|
||||
port: $PORT
|
||||
sources:
|
||||
- path: "$SRC_DIR"
|
||||
name: "RootFS"
|
||||
config:
|
||||
denyByDefault: false
|
||||
rules:
|
||||
- neverWatchPath: "/proc"
|
||||
- neverWatchPath: "/sys"
|
||||
- neverWatchPath: "/dev"
|
||||
- neverWatchPath: "/run"
|
||||
- neverWatchPath: "/tmp"
|
||||
- neverWatchPath: "/lost+found"
|
||||
indexingIntervalMinutes: 240
|
||||
conditionals:
|
||||
rules:
|
||||
- neverWatchPath: "/proc"
|
||||
- neverWatchPath: "/sys"
|
||||
- neverWatchPath: "/dev"
|
||||
- neverWatchPath: "/run"
|
||||
- neverWatchPath: "/tmp"
|
||||
- neverWatchPath: "/lost+found"
|
||||
auth:
|
||||
methods:
|
||||
noauth: true
|
||||
@@ -217,21 +196,22 @@ EOF
|
||||
msg_ok "Configured with no authentication"
|
||||
else
|
||||
cat <<EOF >"$CONFIG_PATH"
|
||||
http:
|
||||
port: $PORT
|
||||
server:
|
||||
port: $PORT
|
||||
sources:
|
||||
- path: "$SRC_DIR"
|
||||
name: "RootFS"
|
||||
config:
|
||||
denyByDefault: false
|
||||
rules:
|
||||
- neverWatchPath: "/proc"
|
||||
- neverWatchPath: "/sys"
|
||||
- neverWatchPath: "/dev"
|
||||
- neverWatchPath: "/run"
|
||||
- neverWatchPath: "/tmp"
|
||||
- neverWatchPath: "/lost+found"
|
||||
indexingIntervalMinutes: 240
|
||||
conditionals:
|
||||
rules:
|
||||
- neverWatchPath: "/proc"
|
||||
- neverWatchPath: "/sys"
|
||||
- neverWatchPath: "/dev"
|
||||
- neverWatchPath: "/run"
|
||||
- neverWatchPath: "/tmp"
|
||||
- neverWatchPath: "/lost+found"
|
||||
auth:
|
||||
adminUsername: admin
|
||||
adminPassword: community-scripts.org
|
||||
|
||||
Reference in New Issue
Block a user