ProxMenux 1.2.6.2-beta: OCI containers in the Monitor, docs and fixes

OCI manager Apps
- App tab: containers installed from an OCI image are identified from their
  installation record; the application and image versions are shown and an
  update is detected by image digest; repository link; Refresh data.
- Updates tab for OCI containers: Update and Recreate run the same flow as the
  OCI menu in the Monitor terminal; the pre-update backup can be kept in a
  backup storage; scheduled image updates with an optional minimum age.
- Logs tab: console output of the application, kept on the host
  (lxc.console.logfile + logrotate) and followed live.
- The Proxmox console opens a shell (cmode: shell) when the image has one.
- A damaged image download is fetched again before failing.
- Multi-container applications open at their LAN address; volume mount
  points on block storage report their usage.

Monitor
- Proxmox notifications are delivered to a loopback-only HTTP listener when
  HTTPS is enabled, so they no longer fail certificate verification.
- Log persistence counts recurring patterns only; an ended burst is not
  reported as persistent and its warning clears on its own (#386).
- Proxmox notification config backups are deduplicated and capped at three.
- The update icon on the Apps page opens the container on its Updates tab.
- Version 1.2.6.2-beta and its release notes in every Monitor language.

Docs
- OCI manager Apps and Audit & Report rebuilt as per-page message files,
  with a new page for OCI containers in the Monitor.
- Seven pages fixed where rich-text tags were missing from t.rich.

Translations
- Spanish fixes across the OCI engine, the Monitor and the TUI menus.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
MacRimi
2026-09-25 21:51:12 +02:00
co-authored by Claude Opus 5.5
parent 386d33df6e
commit 4437a671d2
524 changed files with 14459 additions and 3841 deletions
+20 -23
View File
@@ -226,19 +226,10 @@ INSTALL_COMPLETE=0
PRESERVE_FAILED_CT=0
cleanup_runtime_console_log() {
[[ -n $RUNTIME_CONSOLE_LOG ]] || return 0
if [[ -f ${CONF:-} ]]; then
local temporary_conf
temporary_conf=$(mktemp)
awk '
$0 !~ /^lxc\.console\.logfile:/ &&
$0 !~ /^lxc\.console\.size:/ &&
$0 !~ /^lxc\.console\.rotate:/
' "$CONF" >"$temporary_conf"
cat "$temporary_conf" >"$CONF"
rm -f "$temporary_conf"
fi
rm -f "$RUNTIME_CONSOLE_LOG" "${RUNTIME_CONSOLE_LOG}.1"
# The console log is the container's own log from here on, and its line in
# the configuration stays with it: there is nothing to undo. A failed
# installation keeps the file too, since it holds why the application did
# not come up.
RUNTIME_CONSOLE_LOG=""
}
@@ -1113,7 +1104,7 @@ if [[ $DRY_RUN == 1 ]]; then
fi
# Hold the registry lock through installation so reconciliation cannot race it.
INSTANCE_ROOT=${PROXMENUX_OCI_INSTANCE_ROOT:-/usr/local/share/proxmenux/oci/apps}
INSTANCE_ROOT=${PROXMENUX_OCI_INSTANCE_ROOT:-/usr/local/share/proxmenux/oci/instances}
if [[ -n ${PROXMENUX_OCI_TRANSACTION:-} ]]; then
INSTANCE_ID=$(python3 "${SCRIPT_DIR}/oci_instance_transaction.py" --root "$INSTANCE_ROOT" \
authorize-candidate "$VMID" --journal "$PROXMENUX_OCI_TRANSACTION" \
@@ -1303,8 +1294,7 @@ if [[ ! -s $ARCHIVE_PATH ]]; then
fi
fi
DESCRIPTION="ProxMenux OCI: ${APP_ID}; image=${IMAGE_REF}; digest=${DIGEST}; source=${REVISION}; status=${STATUS}"
DESCRIPTION="${DESCRIPTION}; proxmenux-instance=${INSTANCE_ID}"
DESCRIPTION="proxmenux-instance=${INSTANCE_ID}"
UNPRIVILEGED=$(jq -r 'if .security | has("unprivileged") then .security.unprivileged else true end' "$DEPLOYMENT_FILE")
case "$UNPRIVILEGED" in
true) UNPRIVILEGED_FLAG=1 ;;
@@ -1663,13 +1653,14 @@ CREDENTIALS=$(jq -c --argjson environment "$DEPLOYMENT_ENVIRONMENT" '
' "$TEMPLATE_FILE")
RUNTIME_CREDENTIALS=$(jq '[.[] | select(.retrieval.method? == "container-console-pattern")] | length' <<<"$CREDENTIALS")
if [[ $START_AFTER == 1 && ( $RUNTIME_CREDENTIALS -gt 0 || $HAS_STARTUP_HEALTHCHECK == 1 || $HAS_RUNNING_CHECK == 1 || $HAOS_HEALTHCHECK != 0 ) ]]; then
RUNTIME_CONSOLE_DIR="/run/proxmenux-oci"
install -d -m 700 "$RUNTIME_CONSOLE_DIR"
RUNTIME_CONSOLE_LOG="${RUNTIME_CONSOLE_DIR}/ct-${VMID}.console.log"
install -m 600 /dev/null "$RUNTIME_CONSOLE_LOG"
printf 'lxc.console.logfile: %s\n' "$RUNTIME_CONSOLE_LOG" >>"$CONF"
fi
# The console of the container is kept as its log, the way `docker logs` keeps
# it, and the Proxmox console opens a shell when the image has one. Both are
# set before the configuration is recorded, so the record carries them and an
# update, which rebuilds the container through this installer, sets them again.
# The first-boot credentials are read from the same log.
CONSOLE_STATE=$(python3 "${SCRIPT_DIR}/oci_console.py" configure "$VMID") \
|| die "$(translate "The console of the container could not be configured")"
RUNTIME_CONSOLE_LOG=$(jq -r '.log' <<<"$CONSOLE_STATE")
oci_log "Configuration created for CT $VMID"
PASSWORD_STATE=""
@@ -1870,6 +1861,12 @@ fi
cleanup_runtime_console_log
UPDATED_DESCRIPTION=$(python3 "${SCRIPT_DIR}/oci_description.py" --template "$TEMPLATE_FILE" \
--digest "$DIGEST" --instance "$INSTANCE_ID" --ip "$IP") \
|| die "Could not prepare the OCI notes"
oci_quiet pct set "$VMID" --description "$UPDATED_DESCRIPTION" \
|| die "Could not write the OCI notes in Proxmox"
URLS=$(jq -c --arg ip "$IP" '
if $ip == "" then []
elif (.first_run.endpoints? // []) | length > 0 then