feat(oci): recover applications after a Proxmox reinstall, cluster records and AMD GPU profiles

The installation record of an OCI application travels with its container:
a copy inside the container and another in /etc/pve, written together
with the one kept on the host. A container restored on a newly installed
Proxmox, restored with another ID or moved to another node of a cluster
is recognised and registered again, with its private network, hookscript,
Rclone mount, host firewall rule and NVIDIA runtime. The Monitor offers
the same recovery from the Updates tab.

AMD GPUs are offered by generation. A GPU the ROCm image supports takes
the profile as it is; one of a supported family (Radeon 680M, 780M) is an
experimental option that asks for confirmation and is never proposed; an
older one is not offered. The GPU is checked with a real inference before
the installation accepts it. Recreate changes what runs recognition in an
installed Immich, between the CPU and a GPU of the host.

Updates:
- A failed update that is restored and checked removes its temporary
  container and the disks of the failed attempt.
- Every container volume is part of the backups, so Jellyfin, Plex and
  Hugo update with their default installation.
- An image published with a Docker-format manifest is recognised by its
  layers and build time and updates.
- The Proxmox notes of a multi-container application link to its LAN
  address.
This commit is contained in:
MacRimi
2026-10-04 20:32:17 +02:00
parent 7e9f16fdb3
commit 1f9d2acef5
67 changed files with 4464 additions and 126 deletions
@@ -61,6 +61,7 @@
"rows": [
["Intel/AMD DRM", "<code>/dev/dri/renderD*</code> and <code>/sys/class/drm/NODE/device/vendor</code>", "A character device with vendor <code>0x8086</code> (Intel) or <code>0x1002</code> (AMD)"],
["AMD OpenCL", "The render node, plus <code>/dev/kfd</code> when the profile needs it", "Existence, type, vendor, permissions and declared compatibility"],
["AMD ROCm", "The render node, <code>/dev/kfd</code> and the generation the compute driver reports in <code>/sys/class/kfd/kfd/topology/nodes/*/properties</code>", "A generation the ROCm image of the application carries kernels for, the RDNA2 GPUs it names and newer ones, is offered as it is. The other GPUs of those families, such as the Radeon 680M and 780M, are offered as experimental and are never the proposed option: ROCm does not support them officially, the application presents them as the generation of their family (<code>HSA_OVERRIDE_GFX_VERSION</code>) and the installer asks for confirmation before the larger image is downloaded. An older GPU, such as the integrated graphics of a Ryzen 5000U, is not offered and Immich keeps recognition on the CPU"],
["NVIDIA", "<code>nvidia-smi</code> and <code>nvidia-container-cli</code>", "GPU, UUID, PCI bus, driver version, Toolkit, <code>/dev/nvidia*</code> nodes, binaries and libraries"],
["Coral PCIe/M.2", "<code>/dev/apex_N</code> and its link in <code>/sys/dev/char/MAJOR:MINOR</code>", "Character node, major/minor, owner, GID and permissions"],
["USB and serial", "<code>/dev/ttyUSB*</code>, <code>/dev/ttyACM*</code> or <code>/dev/bus/usb/BBB/DDD</code>", "Character node; for USB also vendor, product and serial when sysfs publishes them"],
+205 -4
View File
@@ -1,7 +1,7 @@
{
"meta": {
"title": "Install, update and recreate | ProxMenux",
"description": "The instance contract of an OCI container and the operations that use it: update, recreate, remove and recovery of an interrupted operation."
"description": "The instance contract of an OCI container and the operations that use it: update, recreate, remove, recovery of an interrupted operation and recovery after a restore on this or another host."
},
"header": {
"title": "Install, update and recreate",
@@ -20,6 +20,9 @@
"code": {
"code": "instances/\n└── 105/\n └── oci-compose.json\n ├── image and resolved digest\n ├── resources and network\n ├── environment (secrets protected)\n ├── container disks and host directories\n ├── hardware profile and devices\n ├── console log and terminal mode\n └── stack membership and lifecycle"
}
},
{
"p": "A copy of the contract travels inside the container, in <code>/.proxmenux/oci-record.json</code>, readable only by root of the container, so a backup of the container always carries the contract it had at that moment. A second copy is kept in <code>/etc/pve/priv/proxmenux/oci</code>, which every node of a cluster shares and only root of the host reads. Both are written after every installation, update and recreation."
}
]
},
@@ -55,7 +58,7 @@
}
},
{
"p": "For a multi-container application the menu offers <strong>Update every container of the application</strong> and the removal. A stack is not recreated."
"p": "For a multi-container application the menu offers <strong>Update every container of the application</strong>, <strong>Recreate</strong> and the removal. Recreate adds or removes the extra paths and devices of the application container without rebuilding anything and, in Immich, changes what runs recognition."
},
{
"figure": {
@@ -155,6 +158,138 @@
}
]
},
{
"id": "restore",
"title": "Backup, restore and another host",
"intro": "A backup made with vzdump or Proxmox Backup Server includes the container, its disks and the copy of its contract. What the installation keeps on the host is not part of it. <strong>Manage installed OCI applications</strong> detects the containers restored on a host that has no contract for them, a new Proxmox installation or another host, and offers to register them again.",
"blocks": [
{
"steps": {
"items": [
{
"title": "Restore the containers in Proxmox",
"body": "From the backup storage, with the original ID or with any free one. A multi-container application needs every one of its containers."
},
{
"title": "Open Manage installed OCI applications",
"body": "The restored containers are listed and the recovery is offered. The <strong>Recover</strong> button of the Updates tab of <monitorLink>ProxMenux Monitor</monitorLink> opens the same recovery."
},
{
"title": "Check before changing",
"body": "The recovery checks that the host has everything each application needs. An application that cannot be recovered whole is left as it was found, with the reason."
},
{
"title": "Register and start",
"body": "The contract is registered on this host and what the installation kept on it is written again. Starting the applications is a separate question, answered with No when the original containers are still running on another host."
}
]
}
},
{
"figure": {
"src": "/oci-manager/restore-offer.png",
"alt": "Dialog that lists the restored containers and offers to recover them",
"caption": "The recovery offered when Manage installed OCI applications opens."
}
},
{
"table": {
"headers": [
"What the host kept",
"After the recovery"
],
"rows": [
[
"Instance contract",
"Registered from the copy the container carries, checked against the configuration Proxmox restored"
],
[
"Private network of a multi-container application",
"Created again with the same bridge and subnet; the fixed addresses of the containers do not change"
],
[
"Start order of a multi-container application",
"The dependency hookscript and its contract are installed again; snippets are enabled on the <code>local</code> storage when no storage accepts them"
],
[
"Network sysctls and host-monitor file",
"Written again in <code>/etc/pve/proxmenux</code>"
],
[
"NVIDIA runtime",
"The hook of an unprivileged container is installed again. A privileged container gets the driver files of this host instead of those of the host it comes from"
],
[
"Rclone mount",
"The hookscript and the programs that publish the mount are written again, with the same views on the host"
],
[
"Host firewall rule of a host monitor",
"Asked again, for its web port and the subnet of the bridge on this host"
],
[
"<code>lost+found</code> of each restored disk",
"Removed when empty; a restore creates it and some applications cannot start with it in their data"
],
[
"Disks restored on another storage",
"The contract is updated to the storage they are on now"
]
]
}
},
{
"p": "A container restored with another ID keeps its application. The contract, its console log, its network sysctls, the hookscript of an Rclone mount and the start order of a multi-container application are registered with the IDs the containers have on this host."
},
{
"table": {
"headers": [
"What stops a recovery",
"What to do"
],
"rows": [
[
"A container of a multi-container application is missing",
"Restore it too; the application is recovered whole"
],
[
"The private subnet is already used on this host",
"The recovery is cancelled and nothing is changed: the addresses of the containers are fixed and are not moved to another subnet"
],
[
"A host directory does not exist",
"Mount or create it with its data; a backup of the container does not include host directories"
],
[
"A device does not exist on this host",
"Connect it, or remove it from the container in Proxmox"
],
[
"An application with NVIDIA on a host without the driver",
"Install the NVIDIA driver and the Container Toolkit"
],
[
"The backup was made before the copy of the contract existed",
"The container stays as an ordinary LXC and is not offered again"
]
]
}
},
{
"calloutInfo": {
"title": "A container that comes back",
"body": "A container restored over itself from an older backup, rolled back to a snapshot or returned from another node carries the contract of the state it is in. When it is selected for an operation and its contract differs from the one of this host, the operation does not start and the container is offered for recovery."
}
},
{
"figure": {
"src": "/oci-manager/restore-result.png",
"alt": "Result of the recovery with the private network, the start order and the registered containers",
"caption": "The result of a recovery, step by step."
}
}
]
},
{
"id": "remove",
"title": "Removing an OCI application",
@@ -180,9 +315,19 @@
"Kept, with its content",
"Other applications may use it"
],
[
"Host files of the container",
"Deleted",
"Its console log, network sysctls, Rclone mount hookscript and its registration in the App tab of ProxMenux Monitor serve no other container"
],
[
"Files several installations share",
"Deleted with the last installation that uses them",
"The host-monitor file and the dependency hookscript of multi-container applications"
],
[
"Instance contract",
"Retired after a successful removal",
"Deleted after a successful removal",
"No CT is associated with it any more"
],
[
@@ -190,10 +335,20 @@
"Released with the stack",
"It has no members left to connect"
],
[
"Network shared by the Arr suite",
"Released with the last application of the suite",
"Each application of the suite is independent and is removed on its own"
],
[
"A single member of a stack",
"Not removed on its own",
"The whole application is removed, so no stack is left incomplete"
],
[
"A container on another node of the cluster",
"Not removed",
"Its record and host files are on the node where it was installed: it is removed there, after migrating it back"
]
]
}
@@ -227,7 +382,53 @@
"title": "Registry and cleanup",
"blocks": [
{
"p": "The registered contracts are compared with the real CTs. A contract is orphaned only when its VMID no longer exists or no longer carries the expected instance identity. The cleanup does not delete volumes or external data by inference."
"p": "When <strong>Manage installed OCI applications</strong> opens, what is left of containers that exist on no node of the cluster is removed first: the saved record of a container deleted from the Proxmox interface, which is kept as history, and the host files a removal left behind. A record with an operation left halfway is kept, because its backup may still be needed. Volumes and host directories are never deleted by inference."
}
]
},
{
"id": "cluster",
"title": "In a cluster: migration and high availability",
"intro": "An OCI container is an ordinary Proxmox LXC: it can be migrated or managed by HA like any other, within the same limits. What it needs to start is kept where every node of the cluster finds it.",
"blocks": [
{
"table": {
"headers": [
"Part",
"On another node of the cluster"
],
"rows": [
[
"Console log",
"The container creates <code>/var/log/proxmenux/oci</code> before it starts, on whichever node runs it. Each node keeps the log of the starts it ran."
],
[
"Network sysctls and host monitor",
"Kept in <code>/etc/pve/proxmenux</code>, which every node of the cluster shares, so a migrated container finds them."
],
[
"Container disks",
"Proxmox moves them with the container. HA needs them on shared storage."
],
[
"Host directories and devices",
"The same rules as any LXC: a host directory must exist on the target node and be marked as shared, and a GPU, Coral or NPU must be present there."
],
[
"ProxMenux record",
"The contract stays on the node where the application was installed, and every node reads the copy kept in <code>/etc/pve/priv/proxmenux/oci</code>. A single-container application that migrates is registered on the node it arrives at when <strong>Manage installed OCI applications</strong> opens or an operation is launched for it. A multi-container application is offered for recovery there, since its private network has to be created on that node."
]
]
}
},
{
"calloutWarning": {
"title": "Not for high availability",
"body": "A multi-container application reaches its members through a private bridge of the node it was installed on, so its members stay on that node. A host monitor, such as Glances in host mode or Netdata, monitors the node it runs on; moving it would monitor another node."
}
},
{
"p": "A backup restored outside the cluster gets the files of <code>/etc/pve/proxmenux</code> the container uses when the application is recovered."
}
]
},
@@ -108,11 +108,15 @@
],
[
"Recreate",
"The recreation editor (resources, network, paths and GPU). It is not offered for a multi-container application."
"The recreation editor (resources, network, paths and GPU). In a multi-container application it adds or removes the extra paths and devices of the application container and, in Immich, changes what runs recognition."
],
[
"Recover",
"Replaces Update when an operation on the container was interrupted, and opens its recovery."
],
[
"Recover (restored container)",
"Shown for a container restored from a backup that has no contract on this host, under <strong>Restored OCI application</strong>. Opens the <lifecycleLink>recovery</lifecycleLink> in the Monitor terminal; Update and Recreate appear once it is registered."
]
]
}
+22 -1
View File
@@ -295,7 +295,7 @@
{
"id": "manage",
"title": "Managing an installed stack",
"intro": "In <strong>Manage installed OCI applications</strong>, any member leads to the whole stack. The menu of a stack offers <strong>Update every container of the application</strong> and <strong>Remove: delete the application and its containers</strong>.",
"intro": "In <strong>Manage installed OCI applications</strong>, any member leads to the whole stack. The menu of a stack offers <strong>Update every container of the application</strong>, <strong>Recreate: add or remove extra paths and devices</strong> and <strong>Remove: delete the application and its containers</strong>.",
"blocks": [
{
"steps": {
@@ -327,6 +327,27 @@
]
}
},
{
"table": {
"headers": [
"Recreate",
"What changes",
"What is kept"
],
"rows": [
[
"Extra paths and devices",
"They are added to or removed from the application container, which restarts. Nothing is rebuilt",
"The data of the application, its database and the other containers"
],
[
"What runs recognition (Immich)",
"The machine learning container takes the image and the devices of the CPU or of a GPU of the host. The whole application is stopped and updated, as in an update",
"The model cache, the library and the database. If anything fails, the previous containers and the previous choice are restored"
]
]
}
},
{
"calloutWarning": {
"title": "A stack without a coordinated replay is not updated",
@@ -61,6 +61,7 @@
"rows": [
["Intel/AMD DRM", "<code>/dev/dri/renderD*</code> y <code>/sys/class/drm/NODO/device/vendor</code>", "Un dispositivo de caracteres con fabricante <code>0x8086</code> (Intel) o <code>0x1002</code> (AMD)"],
["OpenCL AMD", "El render node, más <code>/dev/kfd</code> cuando el perfil lo necesita", "Existencia, tipo, fabricante, permisos y compatibilidad declarada"],
["AMD ROCm", "El nodo de render, <code>/dev/kfd</code> y la generación que declara el driver de cómputo en <code>/sys/class/kfd/kfd/topology/nodes/*/properties</code>", "Una generación para la que la imagen ROCm de la aplicación trae kernels, las GPU RDNA2 que incluye y las posteriores, se ofrece tal cual. Las demás GPU de esas familias, como las Radeon 680M y 780M, se ofrecen como experimentales y nunca son la opción propuesta: ROCm no las soporta oficialmente, la aplicación las presenta como la generación de su familia (<code>HSA_OVERRIDE_GFX_VERSION</code>) y el instalador pide confirmación antes de descargar la imagen, que es más grande. Una GPU anterior, como los gráficos integrados de un Ryzen 5000U, no se ofrece e Immich deja el reconocimiento en la CPU"],
["NVIDIA", "<code>nvidia-smi</code> y <code>nvidia-container-cli</code>", "GPU, UUID, bus PCI, versión del driver, Toolkit, nodos <code>/dev/nvidia*</code>, binarios y librerías"],
["Coral PCIe/M.2", "<code>/dev/apex_N</code> y su enlace en <code>/sys/dev/char/MAJOR:MINOR</code>", "Nodo de caracteres, major/minor, propietario, GID y permisos"],
["USB y serie", "<code>/dev/ttyUSB*</code>, <code>/dev/ttyACM*</code> o <code>/dev/bus/usb/BBB/DDD</code>", "Nodo de caracteres; en USB también fabricante, producto y número de serie cuando sysfs los publica"],
+205 -4
View File
@@ -1,7 +1,7 @@
{
"meta": {
"title": "Instalar, actualizar y recrear | ProxMenux",
"description": "El contrato de instancia de un contenedor OCI y las operaciones que lo usan: actualizar, recrear, eliminar y recuperar una operación interrumpida."
"description": "El contrato de instancia de un contenedor OCI y las operaciones que lo usan: actualizar, recrear, eliminar, recuperar una operación interrumpida y recuperar tras una restauración en este u otro host."
},
"header": {
"title": "Instalar, actualizar y recrear",
@@ -20,6 +20,9 @@
"code": {
"code": "instances/\n└── 105/\n └── oci-compose.json\n ├── imagen y digest resuelto\n ├── recursos y red\n ├── entorno (secretos protegidos)\n ├── discos del contenedor y directorios del host\n ├── perfil de hardware y dispositivos\n ├── log de consola y modo de terminal\n └── pertenencia a una pila y ciclo de vida"
}
},
{
"p": "Una copia del contrato viaja dentro del contenedor, en <code>/.proxmenux/oci-record.json</code>, legible solo por root del contenedor, así que un backup del contenedor lleva siempre el contrato que tenía en ese momento. Una segunda copia se guarda en <code>/etc/pve/priv/proxmenux/oci</code>, que comparten todos los nodos de un clúster y solo lee root del host. Las dos se escriben tras cada instalación, actualización y recreación."
}
]
},
@@ -55,7 +58,7 @@
}
},
{
"p": "Para una aplicación multicontenedor el menú ofrece <strong>Actualizar cada contenedor de la aplicación</strong> y la eliminación. Una pila no se recrea."
"p": "Para una aplicación multicontenedor el menú ofrece <strong>Actualizar cada contenedor de la aplicación</strong>, <strong>Recrear</strong> y la eliminación. Recrear añade o elimina las rutas y los dispositivos extra del contenedor de la aplicación sin reconstruir nada y, en Immich, cambia qué ejecuta el reconocimiento."
},
{
"figure": {
@@ -155,6 +158,138 @@
}
]
},
{
"id": "restore",
"title": "Backup, restauración y otro host",
"intro": "Un backup hecho con vzdump o Proxmox Backup Server incluye el contenedor, sus discos y la copia de su contrato. Lo que la instalación guarda en el host no forma parte de él. <strong>Gestionar aplicaciones OCI instaladas</strong> detecta los contenedores restaurados en un host que no tiene su contrato, un Proxmox recién instalado u otro host, y ofrece registrarlos de nuevo.",
"blocks": [
{
"steps": {
"items": [
{
"title": "Restaurar los contenedores en Proxmox",
"body": "Desde el almacenamiento de backups, con el ID original o con cualquiera libre. Una aplicación de varios contenedores necesita todos sus contenedores."
},
{
"title": "Abrir Gestionar aplicaciones OCI instaladas",
"body": "Se listan los contenedores restaurados y se ofrece la recuperación. El botón <strong>Recuperar</strong> de la pestaña Updates de <monitorLink>ProxMenux Monitor</monitorLink> abre la misma recuperación."
},
{
"title": "Comprobar antes de cambiar",
"body": "La recuperación comprueba que el host tiene todo lo que necesita cada aplicación. Una aplicación que no se puede recuperar entera queda como estaba, con el motivo."
},
{
"title": "Registrar y arrancar",
"body": "El contrato se registra en este host y se escribe de nuevo lo que la instalación guardaba en él. Arrancar las aplicaciones es una pregunta aparte, que se responde con No cuando los contenedores originales siguen en marcha en otro host."
}
]
}
},
{
"figure": {
"src": "/oci-manager/restore-offer.png",
"alt": "Diálogo que lista los contenedores restaurados y ofrece recuperarlos",
"caption": "La recuperación que se ofrece al abrir Gestionar aplicaciones OCI instaladas."
}
},
{
"table": {
"headers": [
"Lo que guardaba el host",
"Tras la recuperación"
],
"rows": [
[
"Contrato de la instancia",
"Se registra desde la copia que lleva el contenedor, comprobada contra la configuración que restauró Proxmox"
],
[
"Red privada de una aplicación de varios contenedores",
"Se crea de nuevo con el mismo bridge y la misma subred; las direcciones fijas de los contenedores no cambian"
],
[
"Orden de arranque de una aplicación de varios contenedores",
"El hookscript de dependencias y su contrato se instalan de nuevo; se activan los snippets en el almacenamiento <code>local</code> cuando ningún almacenamiento los admite"
],
[
"Sysctl de red y archivo del monitor del host",
"Se escriben de nuevo en <code>/etc/pve/proxmenux</code>"
],
[
"Runtime de NVIDIA",
"El hook de un contenedor sin privilegios se instala de nuevo. Un contenedor privilegiado recibe los archivos del driver de este host en lugar de los del host del que viene"
],
[
"Montaje de Rclone",
"El hookscript y los programas que publican el montaje se escriben de nuevo, con las mismas vistas en el host"
],
[
"Regla del firewall del host de un monitor del host",
"Se pregunta de nuevo, para su puerto web y la subred del bridge en este host"
],
[
"<code>lost+found</code> de cada disco restaurado",
"Se elimina cuando está vacío; una restauración lo crea y algunas aplicaciones no arrancan con él entre sus datos"
],
[
"Discos restaurados en otro almacenamiento",
"El contrato se actualiza al almacenamiento en el que están ahora"
]
]
}
},
{
"p": "Un contenedor restaurado con otro ID conserva su aplicación. El contrato, su log de consola, sus sysctl de red, el hookscript de un montaje de Rclone y el orden de arranque de una aplicación de varios contenedores se registran con los ID que tienen los contenedores en este host."
},
{
"table": {
"headers": [
"Qué detiene una recuperación",
"Qué hacer"
],
"rows": [
[
"Falta un contenedor de una aplicación de varios contenedores",
"Restaurarlo también; la aplicación se recupera entera"
],
[
"La subred privada ya se usa en este host",
"La recuperación se cancela y no se cambia nada: las direcciones de los contenedores son fijas y no se mueven a otra subred"
],
[
"Un directorio del host no existe",
"Montarlo o crearlo con sus datos; un backup del contenedor no incluye los directorios del host"
],
[
"Un dispositivo no existe en este host",
"Conectarlo, o eliminarlo del contenedor en Proxmox"
],
[
"Una aplicación con NVIDIA en un host sin el driver",
"Instalar el driver de NVIDIA y el Container Toolkit"
],
[
"El backup es anterior a que existiera la copia del contrato",
"El contenedor queda como un LXC normal y no se vuelve a ofrecer"
]
]
}
},
{
"calloutInfo": {
"title": "Un contenedor que vuelve",
"body": "Un contenedor restaurado sobre sí mismo desde un backup anterior, devuelto a un snapshot o llegado de vuelta desde otro nodo lleva el contrato del estado en el que está. Al seleccionarlo para una operación, si su contrato es distinto del de este host, la operación no empieza y el contenedor se ofrece para recuperarlo."
}
},
{
"figure": {
"src": "/oci-manager/restore-result.png",
"alt": "Resultado de la recuperación con la red privada, el orden de arranque y los contenedores registrados",
"caption": "El resultado de una recuperación, paso a paso."
}
}
]
},
{
"id": "remove",
"title": "Eliminar una aplicación OCI",
@@ -180,9 +315,19 @@
"Se conserva, con su contenido",
"Otras aplicaciones pueden usarlo"
],
[
"Archivos del contenedor en el host",
"Se eliminan",
"Su log de consola, los sysctl de red, el hookscript de montaje del Rclone y su registro en la pestaña App de ProxMenux Monitor no sirven a ningún otro contenedor"
],
[
"Archivos que comparten varias instalaciones",
"Se eliminan con la última instalación que los usa",
"El archivo del monitor del host y el hookscript de dependencias de las aplicaciones de varios contenedores"
],
[
"Contrato de la instancia",
"Se retira tras una eliminación correcta",
"Se elimina tras una eliminación correcta",
"Ya no tiene ningún CT asociado"
],
[
@@ -190,10 +335,20 @@
"Se libera con la pila",
"Ya no le quedan miembros que conectar"
],
[
"Red que comparte la suite Arr",
"Se libera con la última aplicación de la suite",
"Cada aplicación de la suite es independiente y se elimina por separado"
],
[
"Un único miembro de una pila",
"No se elimina por separado",
"Se elimina la aplicación completa, para no dejar ninguna pila incompleta"
],
[
"Un contenedor en otro nodo del clúster",
"No se elimina",
"Su registro y sus archivos del host están en el nodo donde se instaló: se elimina allí, después de migrarlo de vuelta"
]
]
}
@@ -227,7 +382,53 @@
"title": "Registro y limpieza",
"blocks": [
{
"p": "Los contratos registrados se comparan con los CT reales. Un contrato solo queda huérfano cuando su VMID ya no existe o ya no lleva la identidad de instancia esperada. La limpieza no elimina volúmenes ni datos externos por deducción."
"p": "Al abrir <strong>Gestionar aplicaciones OCI instaladas</strong>, primero se elimina lo que quede de contenedores que no existen en ningún nodo del clúster: el registro guardado de un contenedor borrado desde la interfaz de Proxmox, que se conserva como historial, y los archivos del host que dejara una eliminación. Un registro con una operación a medias se conserva, porque su backup puede hacer falta. Los volúmenes y los directorios del host nunca se eliminan por deducción."
}
]
},
{
"id": "cluster",
"title": "En un clúster: migración y alta disponibilidad",
"intro": "Un contenedor OCI es un LXC normal de Proxmox: se puede migrar o gestionar con HA como cualquier otro, con los mismos límites. Lo que necesita para arrancar se guarda donde lo encuentra cualquier nodo del clúster.",
"blocks": [
{
"table": {
"headers": [
"Parte",
"En otro nodo del clúster"
],
"rows": [
[
"Log de consola",
"El contenedor crea <code>/var/log/proxmenux/oci</code> antes de arrancar, en el nodo que lo ejecute. Cada nodo guarda el log de los arranques que ejecutó."
],
[
"Sysctl de red y monitor del host",
"Se guardan en <code>/etc/pve/proxmenux</code>, que comparten todos los nodos del clúster, así que un contenedor migrado los encuentra."
],
[
"Discos del contenedor",
"Proxmox los mueve con el contenedor. HA necesita que estén en un almacenamiento compartido."
],
[
"Directorios del host y dispositivos",
"Las mismas reglas que cualquier LXC: un directorio del host tiene que existir en el nodo de destino y estar marcado como compartido, y una GPU, un Coral o una NPU tienen que estar presentes allí."
],
[
"Registro de ProxMenux",
"El contrato se queda en el nodo donde se instaló la aplicación, y todos los nodos leen la copia guardada en <code>/etc/pve/priv/proxmenux/oci</code>. Una aplicación de un solo contenedor que migra queda registrada en el nodo al que llega al abrir <strong>Gestionar aplicaciones OCI instaladas</strong> o al lanzar una operación sobre ella. Una aplicación de varios contenedores se ofrece para recuperarla allí, porque su red privada tiene que crearse en ese nodo."
]
]
}
},
{
"calloutWarning": {
"title": "No son para alta disponibilidad",
"body": "Una aplicación de varios contenedores comunica a sus miembros por un bridge privado del nodo donde se instaló, así que sus miembros se quedan en ese nodo. Un monitor del host, como Glances en modo host o Netdata, vigila el nodo en el que corre; moverlo haría que vigilara otro nodo."
}
},
{
"p": "Un backup restaurado fuera del clúster recibe los archivos de <code>/etc/pve/proxmenux</code> que usa el contenedor al recuperar la aplicación."
}
]
},
@@ -108,11 +108,15 @@
],
[
"Recrear",
"El editor de la recreación (recursos, red, rutas y GPU). No se ofrece en una aplicación multicontenedor."
"El editor de la recreación (recursos, red, rutas y GPU). En una aplicación multicontenedor añade o elimina las rutas y los dispositivos extra del contenedor de la aplicación y, en Immich, cambia qué ejecuta el reconocimiento."
],
[
"Recuperar",
"Sustituye a Actualizar cuando una operación sobre el contenedor quedó interrumpida, y abre su recuperación."
],
[
"Recuperar (contenedor restaurado)",
"Aparece en un contenedor restaurado desde un backup que no tiene contrato en este host, bajo <strong>Aplicación OCI restaurada</strong>. Abre la <lifecycleLink>recuperación</lifecycleLink> en el terminal del Monitor; Actualizar y Recrear aparecen cuando queda registrado."
]
]
}
+10 -1
View File
@@ -171,7 +171,7 @@
{
"id": "manage",
"title": "Gestión de una pila instalada",
"intro": "En <strong>Gestionar aplicaciones OCI instaladas</strong>, cualquier miembro lleva a la pila completa. El menú de una pila ofrece <strong>Actualizar cada contenedor de la aplicación</strong> y <strong>Eliminar: la aplicación y sus contenedores</strong>.",
"intro": "En <strong>Gestionar aplicaciones OCI instaladas</strong>, cualquier miembro lleva a la pila completa. El menú de una pila ofrece <strong>Actualizar cada contenedor de la aplicación</strong>, <strong>Recrear: añadir o eliminar rutas y dispositivos extra</strong> y <strong>Eliminar: la aplicación y sus contenedores</strong>.",
"blocks": [
{
"steps": {
@@ -185,6 +185,15 @@
]
}
},
{
"table": {
"headers": ["Recrear", "Qué cambia", "Qué se conserva"],
"rows": [
["Rutas y dispositivos extra", "Se añaden al contenedor de la aplicación o se eliminan de él, y el contenedor se reinicia. No se reconstruye nada", "Los datos de la aplicación, su base de datos y los demás contenedores"],
["Qué ejecuta el reconocimiento (Immich)", "El contenedor Machine learning toma la imagen y los dispositivos de la CPU o de una GPU del host. Toda la aplicación se detiene y se actualiza, como en una actualización", "La caché de modelos, la biblioteca y la base de datos. Si algo falla, se restauran los contenedores y la opción anteriores"]
]
}
},
{
"calloutWarning": {
"title": "Una pila sin reproducción coordinada no se actualiza",