mirror of
https://github.com/MacRimi/ProxMenux.git
synced 2026-09-29 18:16:43 +00:00
767 lines
30 KiB
JSON
767 lines
30 KiB
JSON
{
|
|||
|
|
"schema_version": "0.5.0",
|
||
|
|
"kind": "proxmenux.oci-template",
|
||
|
|
"id": "image-maybe",
|
||
|
|
"status": "generated-review-required",
|
||
|
|
"catalog_ui": {
|
||
|
|
"title": {
|
||
|
|
"en_US": "Maybe"
|
||
|
|
},
|
||
|
|
"tagline": {
|
||
|
|
"en_US": "Personal finance management application"
|
||
|
|
},
|
||
|
|
"description": {
|
||
|
|
"en_US": "Maybe is a personal finance management application designed to help you track your expenses, income, and investments in one place. With an intuitive interface and powerful features, Maybe makes it easy to understand your financial situation and make informed decisions about your money.\n\n**Key Features:**\n- **Expense Tracking**: Easily log and categorize your expenses\n- **Income Management**: Track multiple income sources\n- **Investment Monitoring**: Keep an eye on your investments and their performance\n- **Budget Planning**: Create and maintain budgets to control your spending\n- **Financial Reports**: Generate detailed reports to understand your financial habits\n- **AI-Powered Insights**: Get personalized financial advice using AI technology\n\n**Use Cases:**\n- Personal budget management\n- Expense tracking and categorization\n- Investment portfolio monitoring\n- Financial goal setting and tracking\n- Cash flow analysis\n\n**Learn More:**\n- [Maybe GitHub Repository](https://github.com/maybe-finance/maybe)\n"
|
||
|
|
},
|
||
|
|
"category": "finance",
|
||
|
|
"category_label": "Finance & Budgeting",
|
||
|
|
"author": "maybe-finance",
|
||
|
|
"developer": "maybe-finance",
|
||
|
|
"icon": null,
|
||
|
|
"thumbnail": null,
|
||
|
|
"screenshots": [],
|
||
|
|
"architectures": [
|
||
|
|
"amd64",
|
||
|
|
"arm64"
|
||
|
|
],
|
||
|
|
"launch": {
|
||
|
|
"scheme": "http",
|
||
|
|
"port": 3000,
|
||
|
|
"path": "/"
|
||
|
|
},
|
||
|
|
"website": "",
|
||
|
|
"documentation": null,
|
||
|
|
"repository": "https://ghcr.io/maybe-finance/maybe",
|
||
|
|
"tips": [],
|
||
|
|
"mini_changelog": [],
|
||
|
|
"display_version": null,
|
||
|
|
"updated_at": null,
|
||
|
|
"hidden": true,
|
||
|
|
"hidden_reason": "Pending multi-container adaptation; retained for future work"
|
||
|
|
},
|
||
|
|
"source": {
|
||
|
|
"provider": "official",
|
||
|
|
"repository": "https://ghcr.io/maybe-finance/maybe",
|
||
|
|
"revision": "e2a38474cc89874ea285a0f1f67662a4062157b52a4e50ba90b32f45117e18a1",
|
||
|
|
"image_repository_url": "https://ghcr.io/maybe-finance/maybe",
|
||
|
|
"readme_pushed_at": "2026-09-11T10:43:22Z",
|
||
|
|
"compose_sha256": "e2a38474cc89874ea285a0f1f67662a4062157b52a4e50ba90b32f45117e18a1",
|
||
|
|
"generated_at": "2026-09-13T15:48:30+00:00"
|
||
|
|
},
|
||
|
|
"container_contract": {
|
||
|
|
"service_name": "maybe-web",
|
||
|
|
"container_name": "maybe-web",
|
||
|
|
"image": {
|
||
|
|
"reference": "ghcr.io/maybe-finance/maybe:latest",
|
||
|
|
"registry": "ghcr.io",
|
||
|
|
"repository": "ghcr.io/maybe-finance/maybe",
|
||
|
|
"tag": "latest",
|
||
|
|
"digest": null,
|
||
|
|
"pull_policy": "resolve-selected-tag-to-architecture-digest-at-install"
|
||
|
|
},
|
||
|
|
"environment": [
|
||
|
|
{
|
||
|
|
"name": "POSTGRES_USER",
|
||
|
|
"example": "maybe_user",
|
||
|
|
"required": true,
|
||
|
|
"sensitive": false,
|
||
|
|
"source": "docker-compose"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"name": "POSTGRES_PASSWORD",
|
||
|
|
"example": "${GENERATED_POSTGRES_PASSWORD}",
|
||
|
|
"required": true,
|
||
|
|
"sensitive": true,
|
||
|
|
"source": "docker-compose"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"name": "POSTGRES_DB",
|
||
|
|
"example": "maybe_production",
|
||
|
|
"required": true,
|
||
|
|
"sensitive": false,
|
||
|
|
"source": "docker-compose"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"name": "SECRET_KEY_BASE",
|
||
|
|
"example": "${GENERATED_SECRET_KEY_BASE}",
|
||
|
|
"required": true,
|
||
|
|
"sensitive": true,
|
||
|
|
"source": "docker-compose"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"name": "SELF_HOSTED",
|
||
|
|
"example": "true",
|
||
|
|
"required": true,
|
||
|
|
"sensitive": false,
|
||
|
|
"source": "docker-compose"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"name": "RAILS_FORCE_SSL",
|
||
|
|
"example": "false",
|
||
|
|
"required": true,
|
||
|
|
"sensitive": false,
|
||
|
|
"source": "docker-compose"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"name": "RAILS_ASSUME_SSL",
|
||
|
|
"example": "false",
|
||
|
|
"required": true,
|
||
|
|
"sensitive": false,
|
||
|
|
"source": "docker-compose"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"name": "DB_HOST",
|
||
|
|
"example": "maybe-db",
|
||
|
|
"required": true,
|
||
|
|
"sensitive": false,
|
||
|
|
"source": "docker-compose"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"name": "DB_PORT",
|
||
|
|
"example": "5432",
|
||
|
|
"required": true,
|
||
|
|
"sensitive": false,
|
||
|
|
"source": "docker-compose"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"name": "REDIS_URL",
|
||
|
|
"example": "redis://maybe-redis:6379/1",
|
||
|
|
"required": true,
|
||
|
|
"sensitive": false,
|
||
|
|
"source": "docker-compose"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"name": "OPENAI_ACCESS_TOKEN",
|
||
|
|
"example": "${GENERATED_OPENAI_ACCESS_TOKEN}",
|
||
|
|
"required": true,
|
||
|
|
"sensitive": true,
|
||
|
|
"source": "docker-compose"
|
||
|
|
}
|
||
|
|
],
|
||
|
|
"volumes": [
|
||
|
|
{
|
||
|
|
"id": "volume-0",
|
||
|
|
"container_path": "/rails/storage",
|
||
|
|
"compose_source_example": "/DATA/AppData/$AppID/app/storage",
|
||
|
|
"read_only": false,
|
||
|
|
"required": true,
|
||
|
|
"installation_choice": [
|
||
|
|
"managed-volume",
|
||
|
|
"host-bind"
|
||
|
|
],
|
||
|
|
"default": "managed-volume",
|
||
|
|
"managed_volume": {
|
||
|
|
"backup": true,
|
||
|
|
"default_size_gb": 8
|
||
|
|
}
|
||
|
|
}
|
||
|
|
],
|
||
|
|
"ports": [
|
||
|
|
{
|
||
|
|
"container_port": 3000,
|
||
|
|
"published_example": 23000,
|
||
|
|
"protocol": "tcp",
|
||
|
|
"required": true,
|
||
|
|
"proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat"
|
||
|
|
}
|
||
|
|
],
|
||
|
|
"related_services": [
|
||
|
|
{
|
||
|
|
"name": "maybe-worker",
|
||
|
|
"image": "ghcr.io/maybe-finance/maybe:latest"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"name": "maybe-db",
|
||
|
|
"image": "postgres:latest"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"name": "maybe-redis",
|
||
|
|
"image": "redis:latest"
|
||
|
|
}
|
||
|
|
],
|
||
|
|
"restart": "unless-stopped",
|
||
|
|
"stop_grace_period": null,
|
||
|
|
"original_compose": "name: maybe\nservices:\n maybe-web:\n container_name: maybe-web\n image: ghcr.io/maybe-finance/maybe:latest\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/app/storage\n target: /rails/storage\n ports:\n - target: 3000\n published: '23000'\n protocol: tcp\n restart: unless-stopped\n environment:\n POSTGRES_USER: maybe_user\n POSTGRES_PASSWORD: ${GENERATED_POSTGRES_PASSWORD}\n POSTGRES_DB: maybe_production\n SECRET_KEY_BASE: ${GENERATED_SECRET_KEY_BASE}\n SELF_HOSTED: 'true'\n RAILS_FORCE_SSL: 'false'\n RAILS_ASSUME_SSL: 'false'\n DB_HOST: maybe-db\n DB_PORT: 5432\n REDIS_URL: redis://maybe-redis:6379/1\n OPENAI_ACCESS_TOKEN: ${GENERATED_OPENAI_ACCESS_TOKEN}\n depends_on:\n maybe-db:\n condition: service_healthy\n maybe-redis:\n condition: service_healthy\n networks:\n - maybe_net\n deploy:\n resources:\n reservations:\n memory: 1024M\n maybe-worker:\n container_name: maybe-worker\n image: ghcr.io/maybe-finance/maybe:latest\n command:\n - bundle\n - exec\n - sidekiq\n restart: unless-stopped\n depends_on:\n maybe-redis:\n condition: service_healthy\n environment:\n POSTGRES_USER: maybe_user\n POSTGRES_PASSWORD: ${GENERATED_POSTGRES_PASSWORD}\n POSTGRES_DB: maybe_production\n SECRET_KEY_BASE: ${GENERATED_SECRET_KEY_BASE}\n SELF_HOSTED: 'true'\n RAILS_FORCE_SSL: 'false'\n RAILS_ASSUME_SSL: 'false'\n DB_HOST: maybe-db\n DB_PORT: 5432\n REDIS_URL: redis://maybe-redis:6379/1\n OPENAI_ACCESS_TOKEN: ${GENERATED_OPENAI_ACCESS_TOKEN}\n networks:\n - maybe_net\n deploy:\n resources:\n reservations:\n memory: 1024M\n maybe-db:\n container_name: maybe-db\n image: postgres:latest\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/pgdata\n target: /var/lib/postgresql/data\n environment:\n POSTGRES_USER: maybe_user\n POSTGRES_PASSWORD: ${GENERATED_POSTGRES_PASSWORD}\n POSTGRES_DB: maybe_production\n healthcheck:\n test:\n - CMD-SHELL\n - pg_isready -U maybe_user -d maybe_production\n interval: 5s\n timeout: 5s\n retries: 5\n networks:\n - maybe_net\n deploy:\n resources:\n reservations:\n memory: 1024M\n maybe-redis:\n container_name: maybe-redis\n image: redis:latest\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/redis/data\n target: /data\n healthcheck:\n test:\n - CMD\n - redis-cli\n - ping\n interval: 5s\n timeout: 5s\n retries: 5\n networks:\n - maybe_net\n deploy:\n resources:\n reservations:\n memory: 1024M\nnetworks:\n maybe_net:\n driver: bridge\n"
|
||
|
|
},
|
||
|
|
"compose_stack": {
|
||
|
|
"project_name": "maybe",
|
||
|
|
"deployment_model": "one-native-oci-lxc-per-compose-service",
|
||
|
|
"user_experience": "single-application-install",
|
||
|
|
"main_service": "maybe-web",
|
||
|
|
"service_count": 4,
|
||
|
|
"services": [
|
||
|
|
{
|
||
|
|
"name": "maybe-db",
|
||
|
|
"image": "postgres:latest",
|
||
|
|
"is_main": false,
|
||
|
|
"role": "dependency",
|
||
|
|
"vmid_offset": 1,
|
||
|
|
"depends_on": [],
|
||
|
|
"frontend_network": false,
|
||
|
|
"private_network": true,
|
||
|
|
"compose": {
|
||
|
|
"container_name": "maybe-db",
|
||
|
|
"image": "postgres:latest",
|
||
|
|
"restart": "unless-stopped",
|
||
|
|
"volumes": [
|
||
|
|
{
|
||
|
|
"type": "bind",
|
||
|
|
"source": "/DATA/AppData/$AppID/pgdata",
|
||
|
|
"target": "/var/lib/postgresql/data"
|
||
|
|
}
|
||
|
|
],
|
||
|
|
"environment": {
|
||
|
|
"POSTGRES_USER": "maybe_user",
|
||
|
|
"POSTGRES_PASSWORD": "${GENERATED_POSTGRES_PASSWORD}",
|
||
|
|
"POSTGRES_DB": "maybe_production"
|
||
|
|
},
|
||
|
|
"healthcheck": {
|
||
|
|
"test": [
|
||
|
|
"CMD-SHELL",
|
||
|
|
"pg_isready -U maybe_user -d maybe_production"
|
||
|
|
],
|
||
|
|
"interval": "5s",
|
||
|
|
"timeout": "5s",
|
||
|
|
"retries": 5
|
||
|
|
},
|
||
|
|
"networks": [
|
||
|
|
"maybe_net"
|
||
|
|
],
|
||
|
|
"deploy": {
|
||
|
|
"resources": {
|
||
|
|
"reservations": {
|
||
|
|
"memory": "1024M"
|
||
|
|
}
|
||
|
|
}
|
||
|
|
}
|
||
|
|
}
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"name": "maybe-redis",
|
||
|
|
"image": "redis:latest",
|
||
|
|
"is_main": false,
|
||
|
|
"role": "dependency",
|
||
|
|
"vmid_offset": 2,
|
||
|
|
"depends_on": [],
|
||
|
|
"frontend_network": false,
|
||
|
|
"private_network": true,
|
||
|
|
"compose": {
|
||
|
|
"container_name": "maybe-redis",
|
||
|
|
"image": "redis:latest",
|
||
|
|
"restart": "unless-stopped",
|
||
|
|
"volumes": [
|
||
|
|
{
|
||
|
|
"type": "bind",
|
||
|
|
"source": "/DATA/AppData/$AppID/redis/data",
|
||
|
|
"target": "/data"
|
||
|
|
}
|
||
|
|
],
|
||
|
|
"healthcheck": {
|
||
|
|
"test": [
|
||
|
|
"CMD",
|
||
|
|
"redis-cli",
|
||
|
|
"ping"
|
||
|
|
],
|
||
|
|
"interval": "5s",
|
||
|
|
"timeout": "5s",
|
||
|
|
"retries": 5
|
||
|
|
},
|
||
|
|
"networks": [
|
||
|
|
"maybe_net"
|
||
|
|
],
|
||
|
|
"deploy": {
|
||
|
|
"resources": {
|
||
|
|
"reservations": {
|
||
|
|
"memory": "1024M"
|
||
|
|
}
|
||
|
|
}
|
||
|
|
}
|
||
|
|
}
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"name": "maybe-worker",
|
||
|
|
"image": "ghcr.io/maybe-finance/maybe:latest",
|
||
|
|
"is_main": false,
|
||
|
|
"role": "dependency",
|
||
|
|
"vmid_offset": 3,
|
||
|
|
"depends_on": [
|
||
|
|
"maybe-redis"
|
||
|
|
],
|
||
|
|
"frontend_network": false,
|
||
|
|
"private_network": true,
|
||
|
|
"compose": {
|
||
|
|
"container_name": "maybe-worker",
|
||
|
|
"image": "ghcr.io/maybe-finance/maybe:latest",
|
||
|
|
"command": [
|
||
|
|
"bundle",
|
||
|
|
"exec",
|
||
|
|
"sidekiq"
|
||
|
|
],
|
||
|
|
"restart": "unless-stopped",
|
||
|
|
"depends_on": {
|
||
|
|
"maybe-redis": {
|
||
|
|
"condition": "service_healthy"
|
||
|
|
}
|
||
|
|
},
|
||
|
|
"environment": {
|
||
|
|
"POSTGRES_USER": "maybe_user",
|
||
|
|
"POSTGRES_PASSWORD": "${GENERATED_POSTGRES_PASSWORD}",
|
||
|
|
"POSTGRES_DB": "maybe_production",
|
||
|
|
"SECRET_KEY_BASE": "${GENERATED_SECRET_KEY_BASE}",
|
||
|
|
"SELF_HOSTED": "true",
|
||
|
|
"RAILS_FORCE_SSL": "false",
|
||
|
|
"RAILS_ASSUME_SSL": "false",
|
||
|
|
"DB_HOST": "maybe-db",
|
||
|
|
"DB_PORT": 5432,
|
||
|
|
"REDIS_URL": "redis://maybe-redis:6379/1",
|
||
|
|
"OPENAI_ACCESS_TOKEN": "${GENERATED_OPENAI_ACCESS_TOKEN}"
|
||
|
|
},
|
||
|
|
"networks": [
|
||
|
|
"maybe_net"
|
||
|
|
],
|
||
|
|
"deploy": {
|
||
|
|
"resources": {
|
||
|
|
"reservations": {
|
||
|
|
"memory": "1024M"
|
||
|
|
}
|
||
|
|
}
|
||
|
|
}
|
||
|
|
}
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"name": "maybe-web",
|
||
|
|
"image": "ghcr.io/maybe-finance/maybe:latest",
|
||
|
|
"is_main": true,
|
||
|
|
"role": "frontend",
|
||
|
|
"vmid_offset": 0,
|
||
|
|
"depends_on": [
|
||
|
|
"maybe-db",
|
||
|
|
"maybe-redis"
|
||
|
|
],
|
||
|
|
"frontend_network": true,
|
||
|
|
"private_network": true,
|
||
|
|
"compose": {
|
||
|
|
"container_name": "maybe-web",
|
||
|
|
"image": "ghcr.io/maybe-finance/maybe:latest",
|
||
|
|
"volumes": [
|
||
|
|
{
|
||
|
|
"type": "bind",
|
||
|
|
"source": "/DATA/AppData/$AppID/app/storage",
|
||
|
|
"target": "/rails/storage"
|
||
|
|
}
|
||
|
|
],
|
||
|
|
"ports": [
|
||
|
|
{
|
||
|
|
"target": 3000,
|
||
|
|
"published": "23000",
|
||
|
|
"protocol": "tcp"
|
||
|
|
}
|
||
|
|
],
|
||
|
|
"restart": "unless-stopped",
|
||
|
|
"environment": {
|
||
|
|
"POSTGRES_USER": "maybe_user",
|
||
|
|
"POSTGRES_PASSWORD": "${GENERATED_POSTGRES_PASSWORD}",
|
||
|
|
"POSTGRES_DB": "maybe_production",
|
||
|
|
"SECRET_KEY_BASE": "${GENERATED_SECRET_KEY_BASE}",
|
||
|
|
"SELF_HOSTED": "true",
|
||
|
|
"RAILS_FORCE_SSL": "false",
|
||
|
|
"RAILS_ASSUME_SSL": "false",
|
||
|
|
"DB_HOST": "maybe-db",
|
||
|
|
"DB_PORT": 5432,
|
||
|
|
"REDIS_URL": "redis://maybe-redis:6379/1",
|
||
|
|
"OPENAI_ACCESS_TOKEN": "${GENERATED_OPENAI_ACCESS_TOKEN}"
|
||
|
|
},
|
||
|
|
"depends_on": {
|
||
|
|
"maybe-db": {
|
||
|
|
"condition": "service_healthy"
|
||
|
|
},
|
||
|
|
"maybe-redis": {
|
||
|
|
"condition": "service_healthy"
|
||
|
|
}
|
||
|
|
},
|
||
|
|
"networks": [
|
||
|
|
"maybe_net"
|
||
|
|
],
|
||
|
|
"deploy": {
|
||
|
|
"resources": {
|
||
|
|
"reservations": {
|
||
|
|
"memory": "1024M"
|
||
|
|
}
|
||
|
|
}
|
||
|
|
}
|
||
|
|
}
|
||
|
|
}
|
||
|
|
],
|
||
|
|
"top_level": {
|
||
|
|
"name": "maybe",
|
||
|
|
"networks": {
|
||
|
|
"maybe_net": {
|
||
|
|
"driver": "bridge"
|
||
|
|
}
|
||
|
|
}
|
||
|
|
},
|
||
|
|
"networking": {
|
||
|
|
"frontend": "selected-proxmox-bridge",
|
||
|
|
"private_required": true,
|
||
|
|
"private_creation": "automatic-create-if-missing",
|
||
|
|
"private_address_allocation": "automatic-static-address-per-service",
|
||
|
|
"service_discovery": "private-addresses-with-compose-service-host-aliases",
|
||
|
|
"dependency_external_access": "disabled-unless-service-publishes-ports",
|
||
|
|
"prompt_user_for_private_network": false
|
||
|
|
},
|
||
|
|
"storage": [
|
||
|
|
{
|
||
|
|
"id": "maybe-web-volume-0",
|
||
|
|
"service": "maybe-web",
|
||
|
|
"container_path": "/rails/storage",
|
||
|
|
"mode": "managed-volume",
|
||
|
|
"user_selectable": false,
|
||
|
|
"backup": true,
|
||
|
|
"shared_with_other_lxc": false,
|
||
|
|
"source_path": null,
|
||
|
|
"source_path_prompt": null
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"id": "maybe-db-volume-0",
|
||
|
|
"service": "maybe-db",
|
||
|
|
"container_path": "/var/lib/postgresql/data",
|
||
|
|
"mode": "managed-volume",
|
||
|
|
"user_selectable": false,
|
||
|
|
"backup": true,
|
||
|
|
"shared_with_other_lxc": false,
|
||
|
|
"source_path": null,
|
||
|
|
"source_path_prompt": null
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"id": "maybe-redis-volume-0",
|
||
|
|
"service": "maybe-redis",
|
||
|
|
"container_path": "/data",
|
||
|
|
"mode": "host-bind",
|
||
|
|
"user_selectable": true,
|
||
|
|
"backup": false,
|
||
|
|
"shared_with_other_lxc": true,
|
||
|
|
"source_path": null,
|
||
|
|
"source_path_prompt": "Host directory for maybe-redis:/data"
|
||
|
|
}
|
||
|
|
],
|
||
|
|
"orchestration": {
|
||
|
|
"reserve_vmids_atomically": 4,
|
||
|
|
"start_order": [
|
||
|
|
"maybe-db",
|
||
|
|
"maybe-redis",
|
||
|
|
"maybe-worker",
|
||
|
|
"maybe-web"
|
||
|
|
],
|
||
|
|
"stop_order": [
|
||
|
|
"maybe-web",
|
||
|
|
"maybe-worker",
|
||
|
|
"maybe-redis",
|
||
|
|
"maybe-db"
|
||
|
|
],
|
||
|
|
"dependency_readiness": "compose-healthcheck-then-port-or-process-fallback",
|
||
|
|
"rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes"
|
||
|
|
},
|
||
|
|
"installer_inputs": {
|
||
|
|
"prompted": [
|
||
|
|
"stack_name",
|
||
|
|
"base_vmid",
|
||
|
|
"rootfs_storage",
|
||
|
|
"persistent_data_destinations",
|
||
|
|
"frontend_bridge",
|
||
|
|
"frontend_ipv4_mode"
|
||
|
|
],
|
||
|
|
"automatic": [
|
||
|
|
"dependent_vmids",
|
||
|
|
"private_bridge",
|
||
|
|
"private_subnet",
|
||
|
|
"private_service_addresses",
|
||
|
|
"compose_service_aliases",
|
||
|
|
"generated_secrets",
|
||
|
|
"dependency_start_and_stop_order"
|
||
|
|
],
|
||
|
|
"generated_secrets": [
|
||
|
|
{
|
||
|
|
"id": "openai-access-token",
|
||
|
|
"strategy": "generate-cryptographically-random-at-install",
|
||
|
|
"bindings": [
|
||
|
|
{
|
||
|
|
"service": "maybe-web",
|
||
|
|
"environment_variable": "OPENAI_ACCESS_TOKEN"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"service": "maybe-worker",
|
||
|
|
"environment_variable": "OPENAI_ACCESS_TOKEN"
|
||
|
|
}
|
||
|
|
]
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"id": "postgres-password",
|
||
|
|
"strategy": "generate-cryptographically-random-at-install",
|
||
|
|
"bindings": [
|
||
|
|
{
|
||
|
|
"service": "maybe-web",
|
||
|
|
"environment_variable": "POSTGRES_PASSWORD"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"service": "maybe-worker",
|
||
|
|
"environment_variable": "POSTGRES_PASSWORD"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"service": "maybe-db",
|
||
|
|
"environment_variable": "POSTGRES_PASSWORD"
|
||
|
|
}
|
||
|
|
]
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"id": "secret-key-base",
|
||
|
|
"strategy": "generate-cryptographically-random-at-install",
|
||
|
|
"bindings": [
|
||
|
|
{
|
||
|
|
"service": "maybe-web",
|
||
|
|
"environment_variable": "SECRET_KEY_BASE"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"service": "maybe-worker",
|
||
|
|
"environment_variable": "SECRET_KEY_BASE"
|
||
|
|
}
|
||
|
|
]
|
||
|
|
}
|
||
|
|
]
|
||
|
|
}
|
||
|
|
},
|
||
|
|
"first_run": {
|
||
|
|
"endpoints": [
|
||
|
|
{
|
||
|
|
"label": "Web UI",
|
||
|
|
"scheme": "http",
|
||
|
|
"port": 3000,
|
||
|
|
"path": "/",
|
||
|
|
"source": "compose-metadata"
|
||
|
|
}
|
||
|
|
],
|
||
|
|
"credentials": []
|
||
|
|
},
|
||
|
|
"proxmox": {
|
||
|
|
"runtime": "native-oci-lxc",
|
||
|
|
"technology_status": "proxmox-technology-preview",
|
||
|
|
"defaults": {
|
||
|
|
"unprivileged": true,
|
||
|
|
"ostype": "auto-from-image",
|
||
|
|
"cores": 2,
|
||
|
|
"memory_mb": 1024,
|
||
|
|
"swap_mb": 512,
|
||
|
|
"rootfs_size_gb": 8,
|
||
|
|
"rootfs_storage": "local-lvm",
|
||
|
|
"volume_storage": "local-lvm",
|
||
|
|
"template_storage": "local",
|
||
|
|
"bridge": "vmbr0",
|
||
|
|
"ipv4": "dhcp",
|
||
|
|
"firewall": true,
|
||
|
|
"host_managed_network": true,
|
||
|
|
"onboot": false,
|
||
|
|
"features": [
|
||
|
|
"nesting=1"
|
||
|
|
],
|
||
|
|
"shutdown_timeout_seconds": 30
|
||
|
|
},
|
||
|
|
"image_metadata_policy": {
|
||
|
|
"entrypoint": "import-from-oci-image",
|
||
|
|
"cmd": "import-from-oci-image",
|
||
|
|
"environment": "import-image-env-then-apply-compose-overrides",
|
||
|
|
"user": "import-from-oci-image",
|
||
|
|
"working_dir": "import-from-oci-image",
|
||
|
|
"stop_signal": "import-from-oci-image"
|
||
|
|
},
|
||
|
|
"adaptations": [
|
||
|
|
{
|
||
|
|
"id": "imported-compose-source",
|
||
|
|
"upstream_behavior": "The source definition deploys the complete Docker Compose application model.",
|
||
|
|
"native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.",
|
||
|
|
"reason": "Catalog import must not imply runtime compatibility.",
|
||
|
|
"behavioral_impact": "No automatic installation before review.",
|
||
|
|
"validation": "pending-per-application"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"id": "rolling-latest-image",
|
||
|
|
"upstream_behavior": "A discovered Compose may pin a release tag or digest.",
|
||
|
|
"native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.",
|
||
|
|
"reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.",
|
||
|
|
"behavioral_impact": "The installed release can be newer than the discovered Compose revision.",
|
||
|
|
"validation": "pending-per-application"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"id": "dedicated-lxc-network",
|
||
|
|
"upstream_behavior": "Docker publishes selected container ports on the Docker host.",
|
||
|
|
"native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.",
|
||
|
|
"reason": "A native LXC has its own address and does not require Docker port NAT.",
|
||
|
|
"behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.",
|
||
|
|
"validation": "pending-per-application"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"id": "compose-shm-size",
|
||
|
|
"upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.",
|
||
|
|
"native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.",
|
||
|
|
"reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.",
|
||
|
|
"behavioral_impact": "None expected.",
|
||
|
|
"validation": "not-requested-by-compose"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"id": "compose-command",
|
||
|
|
"upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.",
|
||
|
|
"native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.",
|
||
|
|
"reason": "Proxmox stores the effective OCI process as one entrypoint string.",
|
||
|
|
"behavioral_impact": "None expected.",
|
||
|
|
"validation": "not-requested-by-compose"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"id": "compose-privileged-mode",
|
||
|
|
"upstream_behavior": "Compose selects whether the container runs in privileged mode.",
|
||
|
|
"native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.",
|
||
|
|
"reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.",
|
||
|
|
"behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.",
|
||
|
|
"validation": "native-equivalent"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"id": "compose-process-runtime",
|
||
|
|
"upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.",
|
||
|
|
"native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.",
|
||
|
|
"reason": "The OCI process must start with the same identity, command and working directory without Docker.",
|
||
|
|
"behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.",
|
||
|
|
"validation": "not-requested-by-compose"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"id": "compose-healthcheck",
|
||
|
|
"upstream_behavior": "Docker periodically executes the declared container healthcheck.",
|
||
|
|
"native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.",
|
||
|
|
"reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.",
|
||
|
|
"behavioral_impact": "The check runs during installation rather than continuously after installation.",
|
||
|
|
"validation": "not-requested-by-compose"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"id": "compose-cpu-priority",
|
||
|
|
"upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.",
|
||
|
|
"native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.",
|
||
|
|
"reason": "Both settings express relative CPU priority on different scales.",
|
||
|
|
"behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.",
|
||
|
|
"validation": "not-requested-by-compose"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"id": "compose-network-identity",
|
||
|
|
"upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.",
|
||
|
|
"native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.",
|
||
|
|
"reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.",
|
||
|
|
"behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.",
|
||
|
|
"validation": "pending-per-application"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"id": "compose-network-mode",
|
||
|
|
"upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.",
|
||
|
|
"native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.",
|
||
|
|
"reason": "The LXC is the application host and already has its own address and port namespace.",
|
||
|
|
"behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.",
|
||
|
|
"validation": "not-requested-by-compose"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"id": "compose-capabilities-and-sysctls",
|
||
|
|
"upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.",
|
||
|
|
"native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.",
|
||
|
|
"reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.",
|
||
|
|
"behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.",
|
||
|
|
"validation": "not-requested-by-compose"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"id": "docker-engine-metadata",
|
||
|
|
"upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.",
|
||
|
|
"native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.",
|
||
|
|
"reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.",
|
||
|
|
"behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.",
|
||
|
|
"validation": "not-requested-by-compose"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"id": "compose-device-passthrough",
|
||
|
|
"upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.",
|
||
|
|
"native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.",
|
||
|
|
"reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.",
|
||
|
|
"behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.",
|
||
|
|
"validation": "not-requested-by-compose"
|
||
|
|
},
|
||
|
|
{
|
||
|
|
"id": "compose-host-ipc",
|
||
|
|
"upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.",
|
||
|
|
"native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.",
|
||
|
|
"reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.",
|
||
|
|
"behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.",
|
||
|
|
"validation": "not-requested-by-compose"
|
||
|
|
}
|
||
|
|
],
|
||
|
|
"generic_stack_review": [
|
||
|
|
"maybe-worker: perfil de salud y persistencia pendiente"
|
||
|
|
]
|
||
|
|
},
|
||
|
|
"compatibility": {
|
||
|
|
"automatic_install_candidate": false,
|
||
|
|
"validated": false,
|
||
|
|
"supported_compose_keys": [
|
||
|
|
"cap_add",
|
||
|
|
"command",
|
||
|
|
"container_name",
|
||
|
|
"cpu_shares",
|
||
|
|
"deploy",
|
||
|
|
"devices",
|
||
|
|
"entrypoint",
|
||
|
|
"environment",
|
||
|
|
"extra_hosts",
|
||
|
|
"healthcheck",
|
||
|
|
"hostname",
|
||
|
|
"image",
|
||
|
|
"init",
|
||
|
|
"ipc",
|
||
|
|
"labels",
|
||
|
|
"logging",
|
||
|
|
"mac_address",
|
||
|
|
"network_mode",
|
||
|
|
"networks",
|
||
|
|
"ports",
|
||
|
|
"privileged",
|
||
|
|
"restart",
|
||
|
|
"runtime",
|
||
|
|
"shm_size",
|
||
|
|
"stdin_open",
|
||
|
|
"stop_grace_period",
|
||
|
|
"sysctls",
|
||
|
|
"tty",
|
||
|
|
"user",
|
||
|
|
"volumes",
|
||
|
|
"working_dir"
|
||
|
|
],
|
||
|
|
"untranslated_blockers": [
|
||
|
|
"multi-service-compose",
|
||
|
|
"compose-key:depends_on",
|
||
|
|
"service:maybe-worker:compose-key:depends_on",
|
||
|
|
"service:maybe-db:healthcheck-format",
|
||
|
|
"service:maybe-redis:healthcheck-format",
|
||
|
|
"native-multi-lxc-orchestrator-not-yet-implemented"
|
||
|
|
],
|
||
|
|
"policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available."
|
||
|
|
},
|
||
|
|
"validation": {
|
||
|
|
"schema": "passed-at-generation",
|
||
|
|
"clean_install": "pending",
|
||
|
|
"service_health": "pending",
|
||
|
|
"restart_persistence": "pending",
|
||
|
|
"backup_restore": "pending",
|
||
|
|
"update_preserves_data": "pending"
|
||
|
|
},
|
||
|
|
"lifecycle": {
|
||
|
|
"update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update",
|
||
|
|
"registry_state": {
|
||
|
|
"resolved_architecture": null,
|
||
|
|
"resolved_digest": null,
|
||
|
|
"image_version_label": null,
|
||
|
|
"image_created": null
|
||
|
|
},
|
||
|
|
"change_detection": "compare-compose-sha256-and-resolved-latest-image-digest",
|
||
|
|
"automatic_unattended_updates": false
|
||
|
|
}
|
||
|
|
}
|