mirror of
https://github.com/MacRimi/ProxMenux.git
synced 2026-10-08 22:46:41 +00:00
This commit is contained in:
@@ -250,7 +250,7 @@ export default async function NvidiaHostPage({
|
||||
|
||||
<Steps.Step title={t("walkthrough.version.title")}>
|
||||
<p className="mb-3 text-gray-800">{t.rich("walkthrough.version.body1", { strong, em, code })}</p>
|
||||
<p className="mb-3 text-gray-800">{t("walkthrough.version.body2")}</p>
|
||||
<p className="mb-3 text-gray-800">{t.rich("walkthrough.version.body2", { em })}</p>
|
||||
|
||||
<Callout variant="tip" title={t("walkthrough.version.whyTitle")}>
|
||||
{t("walkthrough.version.whyBody")}
|
||||
|
||||
@@ -49,6 +49,7 @@ export async function generateMetadata({
|
||||
type SourceRow = { collector: string; watches: string; events: string }
|
||||
type DispatchRow = { stage: string; what: string; tunable: string }
|
||||
type CatalogueRow = { group: string; events: string }
|
||||
type BackupResultRow = { icon: string; result: string; when: string }
|
||||
type ApiRow = { endpoint: string; method: string; use: string }
|
||||
type WhereNextItem = { label: string; href: string; tail?: string; tailRich?: string }
|
||||
|
||||
@@ -88,7 +89,7 @@ export default async function NotificationsPage({
|
||||
securityItems: string[]
|
||||
actionsItems: string[]
|
||||
}
|
||||
catalogue: { rows: CatalogueRow[] }
|
||||
catalogue: { rows: CatalogueRow[]; backupResults: { rows: BackupResultRow[]; items: string[] } }
|
||||
api: { rows: ApiRow[] }
|
||||
whereNext: { items: WhereNextItem[] }
|
||||
} } }
|
||||
@@ -117,6 +118,8 @@ export default async function NotificationsPage({
|
||||
const pveSecurity = n.pveWebhook.securityItems
|
||||
const pveActions = n.pveWebhook.actionsItems
|
||||
const catalogueRows = n.catalogue.rows
|
||||
const backupResultRows = n.catalogue.backupResults.rows
|
||||
const backupResultItems = n.catalogue.backupResults.items
|
||||
const apiRows = n.api.rows
|
||||
const whereNextItems = n.whereNext.items
|
||||
|
||||
@@ -722,6 +725,37 @@ running on node pve-01
|
||||
{t.rich("catalogue.burstNote", { code })}
|
||||
</p>
|
||||
|
||||
<h3 id="backup-results" className="text-lg font-semibold mt-6 mb-2 text-gray-900">{t("catalogue.backupResults.heading")}</h3>
|
||||
|
||||
<p className="mb-4 text-gray-800 leading-relaxed">{t.rich("catalogue.backupResults.intro", { em })}</p>
|
||||
|
||||
<div className="overflow-x-auto mb-6">
|
||||
<table className="w-full text-sm border border-gray-200 rounded-md">
|
||||
<thead className="bg-gray-50 text-gray-900">
|
||||
<tr>
|
||||
<th className="text-left px-3 py-2 border-b border-gray-200">{t("catalogue.backupResults.headerIcon")}</th>
|
||||
<th className="text-left px-3 py-2 border-b border-gray-200">{t("catalogue.backupResults.headerResult")}</th>
|
||||
<th className="text-left px-3 py-2 border-b border-gray-200">{t("catalogue.backupResults.headerWhen")}</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody className="text-gray-800">
|
||||
{backupResultRows.map((row, idx) => (
|
||||
<tr key={row.icon} className={idx < backupResultRows.length - 1 ? "border-b border-gray-100" : ""}>
|
||||
<td className="px-3 py-2 align-top whitespace-nowrap">{row.icon}</td>
|
||||
<td className="px-3 py-2 align-top whitespace-nowrap"><strong>{row.result}</strong></td>
|
||||
<td className="px-3 py-2 align-top">{row.when}</td>
|
||||
</tr>
|
||||
))}
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
|
||||
<ul className="list-disc pl-6 mb-6 text-gray-800 leading-relaxed space-y-1">
|
||||
{backupResultItems.map((_, idx) => (
|
||||
<li key={idx}>{t.rich(`catalogue.backupResults.items.${idx}`, { strong })}</li>
|
||||
))}
|
||||
</ul>
|
||||
|
||||
<h2 className="text-2xl font-semibold mt-10 mb-4 text-gray-900">{t("history.heading")}</h2>
|
||||
|
||||
<p className="mb-4 text-gray-800 leading-relaxed">
|
||||
|
||||
@@ -85,14 +85,17 @@ apt-get -y install pigz
|
||||
cat > /bin/pigzwrapper <<'EOF'
|
||||
#!/bin/sh
|
||||
PATH=/bin:$PATH
|
||||
GZIP="-1"
|
||||
export GZIP="-1"
|
||||
exec /usr/bin/pigz "$@"
|
||||
EOF
|
||||
chmod +x /bin/pigzwrapper
|
||||
|
||||
# Only replaces gzip if not already replaced (idempotent)
|
||||
[ ! -f /bin/gzip.original ] && mv /bin/gzip /bin/gzip.original \\
|
||||
&& cp /bin/pigzwrapper /bin/gzip && chmod +x /bin/gzip`}
|
||||
# gzip is diverted: the real binary is kept as gzip.distrib, package updates
|
||||
# land there, and the wrapper takes the place of gzip.
|
||||
# Path on Proxmox VE 9; on Proxmox VE 8 it is /bin/gzip.
|
||||
cp -p /usr/bin/gzip /usr/bin/gzip.distrib
|
||||
dpkg-divert --local --no-rename --divert /usr/bin/gzip.distrib --add /usr/bin/gzip
|
||||
cat /bin/pigzwrapper > /usr/bin/gzip`}
|
||||
className="my-4"
|
||||
/>
|
||||
|
||||
@@ -106,8 +109,9 @@ chmod +x /bin/pigzwrapper
|
||||
|
||||
<CopyableCode
|
||||
code={`# Manual rollback of pigz
|
||||
mv /bin/gzip.original /bin/gzip # restore original binary
|
||||
rm /bin/pigzwrapper
|
||||
cat /usr/bin/gzip.distrib > /usr/bin/gzip # restore the real binary
|
||||
dpkg-divert --local --no-rename --remove /usr/bin/gzip
|
||||
rm /usr/bin/gzip.distrib /bin/pigzwrapper
|
||||
sed -i 's/^pigz: 1/#pigz: 1/' /etc/vzdump.conf
|
||||
# Optional: remove the package
|
||||
apt purge pigz`}
|
||||
|
||||
@@ -74,7 +74,7 @@ export default async function SystemUpdatePage({
|
||||
<div>
|
||||
<DocHeader
|
||||
title={t("header.title")}
|
||||
description={t("header.description")}
|
||||
description={t.rich("header.description", { code, em })}
|
||||
section={t("header.section")}
|
||||
estimatedMinutes={5}
|
||||
scriptPath="utilities/proxmox_update.sh"
|
||||
@@ -175,14 +175,14 @@ export default async function SystemUpdatePage({
|
||||
|
||||
<h2 className="text-2xl font-semibold mt-10 mb-4 text-gray-900">{t("noSub.heading")}</h2>
|
||||
<p className="mb-6 text-gray-800 leading-relaxed">
|
||||
{t.rich("noSub.intro", { code, strong })}
|
||||
{t.rich("noSub.intro", { code, strong, em })}
|
||||
</p>
|
||||
<ol className="list-decimal pl-6 mb-6 text-gray-800 leading-relaxed space-y-1">
|
||||
<ul className="list-disc pl-6 mb-6 text-gray-800 leading-relaxed space-y-1">
|
||||
{noSubItems.map((_, idx) => (
|
||||
<li key={idx}>{t.rich(`noSub.items.${idx}`, { code, strong })}</li>
|
||||
<li key={idx}>{t.rich(`noSub.items.${idx}`, { code, strong, em })}</li>
|
||||
))}
|
||||
</ol>
|
||||
<p className="mb-6 text-gray-800 leading-relaxed">{t("noSub.outro")}</p>
|
||||
</ul>
|
||||
<p className="mb-6 text-gray-800 leading-relaxed">{t.rich("noSub.outro", { code, em })}</p>
|
||||
|
||||
<h2 className="text-2xl font-semibold mt-10 mb-4 text-gray-900">{t("cluster.heading")}</h2>
|
||||
<Callout variant="warning" title={t("cluster.calloutTitle")}>
|
||||
@@ -200,7 +200,7 @@ export default async function SystemUpdatePage({
|
||||
|
||||
{troubleItems.map((_, idx) => (
|
||||
<Callout key={idx} variant="troubleshoot" title={t(`troubleshooting.items.${idx}.title`)}>
|
||||
{t.rich(`troubleshooting.items.${idx}.body`, { code, kbd })}
|
||||
{t.rich(`troubleshooting.items.${idx}.body`, { code, kbd, em })}
|
||||
</Callout>
|
||||
))}
|
||||
|
||||
|
||||
@@ -157,7 +157,7 @@ export default async function SystemUtilsPage({
|
||||
<h2 className="text-2xl font-semibold mt-10 mb-4 text-gray-900">{t("troubleshoot.heading")}</h2>
|
||||
|
||||
<Callout variant="troubleshoot" title={t("troubleshoot.reposTitle")}>
|
||||
{t.rich("troubleshoot.reposBody", { code })}
|
||||
{t.rich("troubleshoot.reposBody", { code, em })}
|
||||
</Callout>
|
||||
|
||||
<Callout variant="troubleshoot" title={t("troubleshoot.warningsTitle")}>
|
||||
|
||||
@@ -60,6 +60,7 @@
|
||||
"title": "Prepare the system",
|
||||
"body": "Behind a single confirmation, the script:",
|
||||
"items": [
|
||||
"Checks the repositories of the host before anything is removed or installed: a host with no active subscription and only the Enterprise repository is asked before switching to no-subscription, and the installation stops when the switch is declined.",
|
||||
"Installs <code>pve-headers-$(uname -r)</code> (or <code>proxmox-headers-$(uname -r)</code>), <code>build-essential</code> and <code>dkms</code>.",
|
||||
"Creates the ProxMenux-owned <code>/etc/modprobe.d/proxmenux-nouveau-blacklist.conf</code> with <code>blacklist nouveau</code> and <code>options nouveau modeset=0</code>, records whether it added the companion line to <code>blacklist.conf</code>, and tries to unload the module immediately.",
|
||||
"Writes <code>/etc/modules-load.d/nvidia-vfio.conf</code> with <code>nvidia</code> and <code>nvidia_uvm</code> so the modules load early at boot."
|
||||
|
||||
@@ -400,7 +400,43 @@
|
||||
"events": "<code>gpu_mode_switch</code>, <code>gpu_passthrough_blocked</code>, <code>pci_passthrough_conflict</code>, <code>ai_model_migrated</code>."
|
||||
}
|
||||
],
|
||||
"burstNote": "A handful of <code>burst_*</code> aggregation types (<code>burst_auth_fail</code>, <code>burst_ip_block</code>, <code>burst_disk_io</code>, etc.) exist only in the dispatcher — they replace bursts of individual events with a single summary message and are not exposed as toggles in the UI. They inherit the on/off state of their parent event type."
|
||||
"burstNote": "A handful of <code>burst_*</code> aggregation types (<code>burst_auth_fail</code>, <code>burst_ip_block</code>, <code>burst_disk_io</code>, etc.) exist only in the dispatcher — they replace bursts of individual events with a single summary message and are not exposed as toggles in the UI. They inherit the on/off state of their parent event type.",
|
||||
"backupResults": {
|
||||
"heading": "Backup results",
|
||||
"intro": "A notification about a Proxmox backup job states how the job ended. The result is read from the report Proxmox sends, and it sets the title, the icon shown with <em>Rich messages</em> on, and the status row of the email.",
|
||||
"headerIcon": "Icon",
|
||||
"headerResult": "Result",
|
||||
"headerWhen": "When",
|
||||
"rows": [
|
||||
{
|
||||
"icon": "💾✅",
|
||||
"result": "Backup complete",
|
||||
"when": "Every guest of the job finished and the report carries no warnings."
|
||||
},
|
||||
{
|
||||
"icon": "💾⚠️",
|
||||
"result": "Backup completed with warnings",
|
||||
"when": "Every guest finished and the report carries at least one warning line."
|
||||
},
|
||||
{
|
||||
"icon": "💾❌",
|
||||
"result": "Backup error reported",
|
||||
"when": "A guest failed, or the job stopped with an error."
|
||||
},
|
||||
{
|
||||
"icon": "💾❔",
|
||||
"result": "Backup outcome unconfirmed",
|
||||
"when": "The report is incomplete or does not state a result for every guest."
|
||||
}
|
||||
],
|
||||
"items": [
|
||||
"<strong>The title names what the job was about.</strong> It carries the storage and, for a job with a single guest, its type, name and ID. A failed job names the guest that failed.",
|
||||
"<strong>The body lists each guest</strong> with its own result, size, duration and archive, followed by a line with the totals of the job.",
|
||||
"<strong>Warnings and errors are listed once.</strong> Repeated lines are shown a single time with the main cause first; past eight lines, the rest is counted in a closing line and stays in the Proxmox task log.",
|
||||
"<strong>A job that fails before its first guest</strong> shows the cause Proxmox gave, for example a storage that does not exist.",
|
||||
"<strong>Summaries keep the result.</strong> A backup listed in the Quiet Hours summary or the Daily Digest carries the icon of its own result."
|
||||
]
|
||||
}
|
||||
},
|
||||
"history": {
|
||||
"heading": "History",
|
||||
|
||||
@@ -21,12 +21,13 @@
|
||||
"Sets <code>pigz: 1</code> in <code>/etc/vzdump.conf</code> so Proxmox's backup tool uses pigz natively.",
|
||||
"Installs the <code>pigz</code> apt package if not already present.",
|
||||
"Writes a wrapper script at <code>/bin/pigzwrapper</code> that forwards every argument to <code>/usr/bin/pigz</code>.",
|
||||
"Moves the original <code>/bin/gzip</code> aside to <code>/bin/gzip.original</code> and replaces <code>/bin/gzip</code> with the wrapper. From now on, <em>anything</em> that calls <code>gzip</code> — logrotate, <code>tar czf</code>, scripts, vzdump — uses pigz transparently."
|
||||
"Registers a dpkg diversion for the system's <code>gzip</code> binary (<code>/usr/bin/gzip</code> on Proxmox VE 9, <code>/bin/gzip</code> on Proxmox VE 8): the real binary is kept beside it as <code>gzip.distrib</code> and the wrapper takes its place. From now on, <em>anything</em> that calls <code>gzip</code> — logrotate, <code>tar czf</code>, scripts, vzdump — uses pigz transparently.",
|
||||
"Checks that the file kept as <code>gzip.distrib</code> is a working gzip before the wrapper is put in place, and reinstalls the <code>gzip</code> package first when it is not. A host that still has the earlier <code>/bin/gzip.original</code> swap is moved to the diversion when the option is applied again."
|
||||
],
|
||||
"replacesTitle": "This replaces a system binary",
|
||||
"replacesBody": "Replacing <code>/bin/gzip</code> with a wrapper is unusual. It is safe (the wrapper produces gzip-compatible output), but worth knowing: scripts that hardcode paths, run inside restrictive chroots, or verify binary hashes may behave differently. The original binary is preserved as <code>/bin/gzip.original</code> so you can always swap it back.",
|
||||
"replacesBody": "Putting a wrapper in the place of <code>gzip</code> is unusual. It is safe (the wrapper produces gzip-compatible output), but worth knowing: scripts that hardcode paths, run inside restrictive chroots, or verify binary hashes may behave differently. The real binary is preserved as <code>gzip.distrib</code>, and because the replacement is a dpkg diversion, an update of the <code>gzip</code> package — or the upgrade from Proxmox VE 8 to 9 — updates that file and leaves the wrapper in place.",
|
||||
"revertTitle": "Reversible from the Uninstall menu",
|
||||
"revertBody": "This optimization is tracked. <link>Uninstall Optimizations</link> restores <code>/bin/gzip.original</code> back into place, removes the <code>pigzwrapper</code>, reverts the two lines added to <code>/etc/vzdump.conf</code>, and runs <code>apt purge pigz</code>. Manual equivalent:",
|
||||
"revertBody": "This optimization is tracked. <link>Uninstall Optimizations</link> copies the real binary from <code>gzip.distrib</code> back over the wrapper, removes the diversion and the <code>pigzwrapper</code>, comments out the <code>pigz</code> line in <code>/etc/vzdump.conf</code>, and runs <code>apt purge pigz</code> once gzip is verified to work. Manual equivalent on Proxmox VE 9:",
|
||||
"verifyTitle": "Verification",
|
||||
"verifyBody": "After applying, <code>gzip --version</code> should mention pigz. A quick benchmark also shows the speed difference on a multi-core host:",
|
||||
"whenTitle": "When this matters most",
|
||||
|
||||
@@ -205,7 +205,7 @@
|
||||
},
|
||||
{
|
||||
"tool": "pigz (parallel gzip)",
|
||||
"restores": "Puts /bin/gzip.original back in place, removes the /bin/pigzwrapper, reverts the pigz and bwlimit lines in /etc/vzdump.conf and apt purges pigz."
|
||||
"restores": "Copies the real gzip back from gzip.distrib, removes the dpkg diversion and /bin/pigzwrapper, comments out the pigz line in /etc/vzdump.conf and apt purges pigz once gzip is verified."
|
||||
},
|
||||
{
|
||||
"tool": "High Availability services",
|
||||
|
||||
@@ -78,7 +78,7 @@
|
||||
},
|
||||
{
|
||||
"title": "Proxmox System Update",
|
||||
"description": "Repo hygiene + apt update + apt dist-upgrade with reboot prompt. Detects PVE major version (8 or 9) and routes to the matching worker. Switches to no-subscription, removes conflicting packages, runs autoremove.",
|
||||
"description": "Repository check + apt update + apt dist-upgrade with reboot prompt. Detects the PVE major version (8 or 9), keeps the configured repositories and asks before switching a host without subscription to no-subscription, then runs autoremove.",
|
||||
"href": "/docs/utils/system-update"
|
||||
},
|
||||
{
|
||||
|
||||
@@ -7,7 +7,7 @@
|
||||
},
|
||||
"header": {
|
||||
"title": "Proxmox System Update",
|
||||
"description": "Wrapper that delegates to a single safe worker (<code>update-pve-safe.sh</code>) which detects the running Proxmox major version by itself. Repositories are cleaned up when they overlap with the base Proxmox / Debian sources, all packages are upgraded, ProxMenux-managed DKMS drivers are rebuilt if a new kernel landed, and the reboot prompt fires only when the kernel actually changed. Also launchable from the <em>Update Now</em> button in the ProxMenux Monitor dashboard header when pending updates are detected.",
|
||||
"description": "Wrapper that delegates to a single safe worker (<code>update-pve-safe.sh</code>) which detects the running Proxmox major version by itself. The configured repositories are read through the Proxmox API and kept as they are; a host with no active subscription whose only Proxmox repository is Enterprise is asked before switching to no-subscription. All packages are upgraded, ProxMenux-managed DKMS drivers are rebuilt if a new kernel landed, and the reboot prompt fires only when the kernel actually changed. Also launchable from the <em>Update Now</em> button in the ProxMenux Monitor dashboard header when pending updates are detected.",
|
||||
"section": "Utilities"
|
||||
},
|
||||
"calloutWhat": {
|
||||
@@ -25,7 +25,7 @@
|
||||
"intro": "This option runs <strong>exactly</strong> the apt command above, wrapped with the repo hygiene, DKMS rebuild for ProxMenux-managed drivers and post-upgrade cleanup the official upgrade guide also recommends. Everything below maps 1:1 to <code>scripts/utilities/proxmox_update.sh</code> and the single safe worker <code>scripts/global/update-pve-safe.sh</code> — nothing implied, every step is in the code:",
|
||||
"items": [
|
||||
"<strong>Detects the PVE major version</strong> from inside the worker (<code>pveversion | grep -oP ''pve-manager/\\K[0-9]+''</code>) and adapts the base Proxmox / Debian repo URLs (bookworm on PVE 8, trixie on PVE 9). There is no fan-out to per-version worker scripts — a single safe worker handles both.",
|
||||
"<strong>Cleans up repositories in a conservative way.</strong> <code>ensure_repositories</code> runs first but only when the base Proxmox / Debian sources are missing — a bare host gets them written, a configured host is a no-op. <code>cleanup_duplicate_repos</code> then removes exact URL + Suite + Component duplicates only against <code>proxmox.sources</code> / <code>debian.sources</code>; user-authored files (enterprise, Ceph, alternative NTP mirrors, custom <code>download.proxmox.com/*</code> entries or hand-written <code>pve-*.list</code>) are left untouched, and every file is backed up before being edited.",
|
||||
"<strong>Keeps the configured repositories.</strong> <code>ensure_repositories</code> reads the repositories through the Proxmox repository API, together with the subscription status. A host with an active subscription, or one that already uses the no-subscription or test repository, is left unchanged. A host with no active subscription whose only Proxmox repository is Enterprise is asked whether to switch to no-subscription; declining stops the update with no source changed.",
|
||||
"<strong>Runs the upgrade non-interactively</strong> with <code>DEBIAN_FRONTEND=noninteractive</code> and <code>--force-confdef --force-confold</code> — if a configuration file you already modified also changed upstream, your version stays in place. No silent overwrites of custom configs.",
|
||||
"<strong>Skips forcing optional utilities.</strong> The safe worker does not push <code>zfsutils-linux</code>, <code>chrony</code>, <code>ifupdown2</code> or similar packages onto the host — a Proxmox install that opted out of any of them keeps its choice. Missing packages are surfaced by the higher-level installer flows, not by the update path.",
|
||||
"<strong>LVM metadata sanity check</strong> against stray PV headers from passthrough disks (warn-only, no automatic fix).",
|
||||
@@ -63,10 +63,9 @@
|
||||
"heading": "What the worker does",
|
||||
"intro": "A single worker (<code>scripts/global/update-pve-safe.sh</code>) handles both PVE 8 and PVE 9. It detects the major version internally and uses the version-appropriate codename (<code>bookworm</code> or <code>trixie</code>) for its base sources. The stages are:",
|
||||
"items": [
|
||||
"<strong>Sanity checks.</strong> Verifies at least ~1 GB free in <code>/var/cache/apt/archives</code> and pings <code>download.proxmox.com</code>. Aborts early with a clear message when either fails, so the run doesn't die in the middle of an apt transaction.",
|
||||
"<strong>Repo bootstrap.</strong> <code>ensure_repositories</code> writes the base Proxmox / Debian sources only when they are missing (a fresh or hand-cleaned host); on a configured host it does nothing.",
|
||||
"<strong>Sanity checks.</strong> Verifies at least ~1 GB free in <code>/var/cache/apt/archives</code>. Aborts early with a clear message when it fails, so the run doesn't die in the middle of an apt transaction.",
|
||||
"<strong>Repository check.</strong> <code>ensure_repositories</code> reads the repositories and the subscription status. On a host with a usable Proxmox repository it changes nothing; on a host with no active subscription and only the Enterprise repository it asks before switching to no-subscription, and stops the update when the answer is no.",
|
||||
"<strong>Apt update with GPG auto-recovery.</strong> On <code>NO_PUBKEY</code> for any repo (yours or a third-party one) the worker imports the missing key and retries automatically before failing.",
|
||||
"<strong>Conservative duplicate cleanup.</strong> <code>cleanup_duplicate_repos</code> only removes exact URL + Suite + Component matches against <code>proxmox.sources</code> / <code>debian.sources</code>. User-authored files — enterprise, Ceph, alternative NTP mirrors, custom <code>download.proxmox.com/*</code> entries, hand-written <code>pve-*.list</code> — are left intact. Every file is backed up before modification.",
|
||||
"<strong>Pending upgrades + security count.</strong> Reports how many packages will change and how many of those come from the security suite, so the confirmation dialog has real numbers to show.",
|
||||
"<strong>Confirmation dialog.</strong> The wrapper asks for an explicit yes before touching apt.",
|
||||
"<strong>apt full-upgrade.</strong> Runs with <code>DEBIAN_FRONTEND=noninteractive</code> and <code>--force-confdef --force-confold</code> so any configuration file you customised keeps its current contents when upstream also changed it. Never overwrites operator-edited configs silently.",
|
||||
@@ -96,14 +95,16 @@
|
||||
"body": "Running on an old kernel after upgrading <code>linux-image-*</code> means you're on a half-upgraded system: userspace is new, kernel is old. Most of the time things work, but ZFS modules, IOMMU groups, KSMBD and any out-of-tree drivers will only match the kernel they were built for — a mismatch produces obscure failures. Reboot at the earliest sensible moment."
|
||||
},
|
||||
"noSub": {
|
||||
"heading": "How the safe worker treats the enterprise repo",
|
||||
"intro": "Proxmox ships hosts with the enterprise repo enabled by default. Without a paid subscription, that repo returns 401 on <code>apt-get update</code>. The safe worker deliberately does <strong>not</strong> touch enterprise or Ceph repositories — a host running with a real subscription must not have its config silently rewritten. What happens instead:",
|
||||
"heading": "How the safe worker treats the Enterprise repository",
|
||||
"intro": "Proxmox ships hosts with the Enterprise repository enabled by default. Without an active subscription, that repository returns 401 on <code>apt-get update</code>. The safe worker changes the repositories only in that case, only after asking, and through the Proxmox repository API — the same one behind <em>Node → Updates → Repositories</em>. What happens in each case:",
|
||||
"items": [
|
||||
"On a <strong>bare host</strong> with no base Proxmox / Debian sources at all, <code>ensure_repositories</code> writes the no-subscription source in the deb822 format (<code>proxmox.sources</code>) with the codename matching the detected major version (<code>bookworm</code> for PVE 8, <code>trixie</code> for PVE 9) and the matching Debian sources.",
|
||||
"On a <strong>configured host</strong>, <code>ensure_repositories</code> is a no-op — whatever the operator chose (no-subscription, enterprise, or a mix) is preserved.",
|
||||
"The enterprise <code>pve-enterprise.sources</code> / <code>ceph.sources</code> files are never modified by the update path. The removal of the enterprise repo when it's unwanted is handled elsewhere in ProxMenux (the Automated post-install script), not here."
|
||||
"With an <strong>active subscription</strong>, the repositories are left unchanged and Enterprise drives the upgrade.",
|
||||
"With the <strong>no-subscription or test repository already enabled</strong>, the repositories are left unchanged, whatever else is configured beside them.",
|
||||
"With <strong>no active subscription and only the Enterprise repository</strong>, a dialog offers the switch. Accepting disables the Enterprise source, enables the no-subscription one and refreshes the package lists; the change is recorded in the <em>Changes</em> view of Audit & Report. Declining stops the update with no source changed.",
|
||||
"<strong>Enterprise Ceph sources</strong>, when present, are disabled in the same switch without choosing another Ceph channel; a host that uses Ceph has its channel configured separately.",
|
||||
"When the run has <strong>no terminal to ask in</strong>, no source is changed and the update stops with a message that points to <em>Node → Updates → Repositories</em>."
|
||||
],
|
||||
"outro": "If you have a paid subscription, keep <code>pve-enterprise.sources</code> enabled and the safe worker will let it drive the upgrade unchanged. If you don't, either run the Automated post-install first (it does the switch and records it) or comment the enterprise source out manually — the update path will not do it for you."
|
||||
"outro": "The Debian sources and every other repository file are never edited by the update path. A source that mixes Enterprise with other components in the same entry is not switched: the update stops and asks for it to be split from the Proxmox repository view."
|
||||
},
|
||||
"cluster": {
|
||||
"heading": "Cluster considerations",
|
||||
@@ -124,7 +125,7 @@
|
||||
"items": [
|
||||
{
|
||||
"title": "apt update fails with 401 Unauthorized",
|
||||
"body": "The enterprise repo is still enabled but you don't have a subscription. The worker should detect and switch automatically; if it didn't, comment the line in <code>/etc/apt/sources.list.d/pve-enterprise.list</code> (or set <code>Enabled: false</code> in the deb822 <code>pve-enterprise.sources</code>) and re-run."
|
||||
"body": "The Enterprise repository is enabled and the host has no active subscription. The worker offers the switch to no-subscription before <code>apt-get update</code>; when it was declined, run the update again and accept it, or disable the Enterprise source in <em>Node → Updates → Repositories</em> and enable the no-subscription one."
|
||||
},
|
||||
{
|
||||
"title": "dist-upgrade hangs at \"Configuring grub-pc\"",
|
||||
@@ -142,7 +143,7 @@
|
||||
},
|
||||
"files": {
|
||||
"heading": "Files involved",
|
||||
"code": "scripts/utilities/proxmox_update.sh # this script (wrapper)\nscripts/global/update-pve-safe.sh # single safe worker (PVE 8 + PVE 9)\nscripts/global/common-functions.sh # cleanup_duplicate_repos used by the worker\nscripts/global/utils-install-functions.sh # ensure_repositories + pmx_rebuild_dkms_after_kernel\n/usr/local/share/proxmenux/components_status.json # ProxMenux-managed DKMS driver registry\n/etc/apt/sources.list.d/proxmox.sources # deb822 no-subscription source (bare-host bootstrap)\n/etc/apt/sources.list.d/debian.sources # deb822 Debian sources (bare-host bootstrap)\n/var/run/reboot-required # read to decide on reboot prompt\n# Reboot fallback when needrestart isn't installed:\n# dpkg-query -W 'proxmox-kernel-*-pve-signed' 'pve-kernel-*-pve' vs. uname -r"
|
||||
"code": "scripts/utilities/proxmox_update.sh # this script (wrapper)\nscripts/global/update-pve-safe.sh # single safe worker (PVE 8 + PVE 9)\nscripts/global/repository-functions.sh # ensure_repositories\nscripts/global/repository_policy.py # reads and switches repositories through the Proxmox API\nscripts/global/utils-install-functions.sh # pmx_rebuild_dkms_after_kernel\n/usr/local/share/proxmenux/components_status.json # ProxMenux-managed DKMS driver registry\n/etc/apt/sources.list.d/proxmox.sources # no-subscription source, written by Proxmox when the switch is accepted\n/var/run/reboot-required # read to decide on reboot prompt\n# Reboot fallback when needrestart isn't installed:\n# dpkg-query -W 'proxmox-kernel-*-pve-signed' 'pve-kernel-*-pve' vs. uname -r"
|
||||
},
|
||||
"related": {
|
||||
"heading": "Related",
|
||||
|
||||
@@ -12,7 +12,7 @@
|
||||
},
|
||||
"info": {
|
||||
"title": "What this does",
|
||||
"body": "Installs CLI tools from a curated list of 26 packages. Every installation goes through the same canonical flow: <code>ensure_repositories</code> sets up Proxmox + Debian repos for the running PVE major version, then <code>install_single_package</code> runs the install and verifies the resulting command is in PATH."
|
||||
"body": "Installs CLI tools from a curated list of 26 packages. Every installation goes through the same canonical flow: <code>ensure_repositories</code> checks that the host has a usable Proxmox repository for the running PVE major version, then <code>install_single_package</code> runs the install and verifies the resulting command is in PATH."
|
||||
},
|
||||
"opening": {
|
||||
"heading": "Opening the installer",
|
||||
@@ -204,7 +204,7 @@
|
||||
"howItWorks": {
|
||||
"heading": "How a single package install works",
|
||||
"items": [
|
||||
"<code>ensure_repositories</code> detects PVE 8 or 9, writes Proxmox no-subscription + Debian sources files if missing, runs <code>apt-get update</code>.",
|
||||
"<code>ensure_repositories</code> detects PVE 8 or 9 and reads the repositories through the Proxmox API. A host with a usable Proxmox repository is left unchanged; a host with no active subscription and only the Enterprise repository is asked before switching to no-subscription, and <code>apt-get update</code> runs after an accepted switch.",
|
||||
"<code>install_single_package \"pkg\" \"verify_cmd\" \"description\"</code> runs <code>apt-get install -y \"$pkg\"</code> with feedback (<code>msg_info</code> / <code>msg_ok</code> / <code>msg_error</code>)."
|
||||
],
|
||||
"verifyIntro": "After install, the verify command is checked with <code>command -v \"$verify_cmd\"</code>. Three outcomes:",
|
||||
@@ -224,7 +224,7 @@
|
||||
"troubleshoot": {
|
||||
"heading": "Troubleshooting",
|
||||
"reposTitle": "\"Failed to configure repositories. Installation aborted.\"",
|
||||
"reposBody": "The host can't reach the Proxmox or Debian repos, or doesn't have the expected base config. From a console: <code>cat /etc/apt/sources.list /etc/apt/sources.list.d/*.sources</code> and <code>apt-get update</code> manually to see the actual error.",
|
||||
"reposBody": "The repository check did not pass: the switch to the no-subscription repository was declined, the subscription status could not be read, or a repository entry needs attention. The message printed above it states the cause. The repositories are listed in <em>Node → Updates → Repositories</em>, and <code>apt-get update</code> from a console shows the error apt reports.",
|
||||
"warningsTitle": "A package is reported \"With warnings\" but the command works after I close the menu",
|
||||
"warningsBody": "Expected. After <code>apt-get install</code>, the new binary is on disk but the current shell's PATH cache (<code>hash -t</code>) doesn't know yet. ProxMenux runs <code>hash -r</code> after each install, but in some shells the refresh only takes effect on the next prompt. Open a new shell and the command will work.",
|
||||
"hangsTitle": "An apt install hangs",
|
||||
@@ -232,7 +232,7 @@
|
||||
},
|
||||
"files": {
|
||||
"heading": "Files involved",
|
||||
"code": "scripts/utilities/system_utils.sh # this script\nscripts/global/utils-install-functions.sh # PROXMENUX_UTILS, ensure_repositories,\n # install_single_package\n/etc/apt/sources.list # may be touched by ensure_repositories\n/etc/apt/sources.list.d/proxmox.sources # created if missing (PVE 9)\n/etc/apt/sources.list.d/debian.sources # created if missing (PVE 9)\n/etc/apt/sources.list.d/pve-no-subscription.list # created if missing (PVE 8)"
|
||||
"code": "scripts/utilities/system_utils.sh # this script\nscripts/global/utils-install-functions.sh # PROXMENUX_UTILS, install_single_package\nscripts/global/repository-functions.sh # ensure_repositories\nscripts/global/repository_policy.py # reads and switches repositories through the Proxmox API\n/etc/apt/sources.list.d/proxmox.sources # no-subscription source, written by Proxmox when the switch is accepted"
|
||||
},
|
||||
"related": {
|
||||
"heading": "Related",
|
||||
|
||||
@@ -60,6 +60,7 @@
|
||||
"title": "Preparar el sistema",
|
||||
"body": "Tras una única confirmación, el script:",
|
||||
"items": [
|
||||
"Comprueba los repositorios del host antes de eliminar o instalar nada: en un host sin suscripción activa y solo con el repositorio Enterprise se pregunta antes de cambiar a sin suscripción, y la instalación se detiene cuando el cambio se rechaza.",
|
||||
"Instala <code>pve-headers-$(uname -r)</code> (o <code>proxmox-headers-$(uname -r)</code>), <code>build-essential</code> y <code>dkms</code>.",
|
||||
"Crea el archivo propiedad de ProxMenux <code>/etc/modprobe.d/proxmenux-nouveau-blacklist.conf</code> con <code>blacklist nouveau</code> y <code>options nouveau modeset=0</code>, registra si añadió la línea complementaria a <code>blacklist.conf</code> e intenta descargar el módulo inmediatamente.",
|
||||
"Escribe <code>/etc/modules-load.d/nvidia-vfio.conf</code> con <code>nvidia</code> y <code>nvidia_uvm</code> para que los módulos se carguen pronto en el arranque."
|
||||
|
||||
@@ -400,7 +400,43 @@
|
||||
"events": "<code>gpu_mode_switch</code>, <code>gpu_passthrough_blocked</code>, <code>pci_passthrough_conflict</code>, <code>ai_model_migrated</code>."
|
||||
}
|
||||
],
|
||||
"burstNote": "Un puñado de tipos de agregación <code>burst_*</code> (<code>burst_auth_fail</code>, <code>burst_ip_block</code>, <code>burst_disk_io</code>, etc.) existen solo en el dispatcher — reemplazan ráfagas de eventos individuales con un único mensaje de resumen y no se exponen como toggles en la UI. Heredan el estado on/off de su tipo de evento padre."
|
||||
"burstNote": "Un puñado de tipos de agregación <code>burst_*</code> (<code>burst_auth_fail</code>, <code>burst_ip_block</code>, <code>burst_disk_io</code>, etc.) existen solo en el dispatcher — reemplazan ráfagas de eventos individuales con un único mensaje de resumen y no se exponen como toggles en la UI. Heredan el estado on/off de su tipo de evento padre.",
|
||||
"backupResults": {
|
||||
"heading": "Resultados de backup",
|
||||
"intro": "Una notificación sobre un trabajo de backup de Proxmox indica cómo terminó el trabajo. El resultado se lee del informe que envía Proxmox, y determina el título, el icono que se muestra con <em>Rich messages</em> activado y la fila de estado del email.",
|
||||
"headerIcon": "Icono",
|
||||
"headerResult": "Resultado",
|
||||
"headerWhen": "Cuándo",
|
||||
"rows": [
|
||||
{
|
||||
"icon": "💾✅",
|
||||
"result": "Backup completado",
|
||||
"when": "Todos los guests del trabajo terminaron y el informe no contiene advertencias."
|
||||
},
|
||||
{
|
||||
"icon": "💾⚠️",
|
||||
"result": "Backup completado con advertencias",
|
||||
"when": "Todos los guests terminaron y el informe contiene al menos una línea de advertencia."
|
||||
},
|
||||
{
|
||||
"icon": "💾❌",
|
||||
"result": "Backup fallido",
|
||||
"when": "Un guest falló, o el trabajo se detuvo con un error."
|
||||
},
|
||||
{
|
||||
"icon": "💾❔",
|
||||
"result": "Resultado del backup sin confirmar",
|
||||
"when": "El informe está incompleto o no indica un resultado para cada guest."
|
||||
}
|
||||
],
|
||||
"items": [
|
||||
"<strong>El título indica sobre qué era el trabajo.</strong> Incluye el almacenamiento y, en un trabajo con un solo guest, su tipo, nombre e ID. Un trabajo fallido nombra el guest que falló.",
|
||||
"<strong>El cuerpo lista cada guest</strong> con su propio resultado, tamaño, duración y archivo, seguido de una línea con los totales del trabajo.",
|
||||
"<strong>Las advertencias y los errores se listan una vez.</strong> Las líneas repetidas se muestran una sola vez con la causa principal primero; a partir de ocho líneas, el resto se cuenta en una línea de cierre y permanece en el log de la tarea de Proxmox.",
|
||||
"<strong>Un trabajo que falla antes de su primer guest</strong> muestra la causa que dio Proxmox, por ejemplo un almacenamiento que no existe.",
|
||||
"<strong>Los resúmenes conservan el resultado.</strong> Un backup listado en el resumen de Quiet Hours o en el Daily Digest lleva el icono de su propio resultado."
|
||||
]
|
||||
}
|
||||
},
|
||||
"history": {
|
||||
"heading": "Historial",
|
||||
|
||||
@@ -21,12 +21,13 @@
|
||||
"Establece <code>pigz: 1</code> en <code>/etc/vzdump.conf</code> para que la herramienta de backup de Proxmox use pigz de forma nativa.",
|
||||
"Instala el paquete apt <code>pigz</code> si no está presente.",
|
||||
"Escribe un script wrapper en <code>/bin/pigzwrapper</code> que reenvía todos los argumentos a <code>/usr/bin/pigz</code>.",
|
||||
"Aparta el binario original <code>/bin/gzip</code> a <code>/bin/gzip.original</code> y sustituye <code>/bin/gzip</code> por el wrapper. A partir de ahí, <em>cualquier cosa</em> que llame a <code>gzip</code> — logrotate, <code>tar czf</code>, scripts, vzdump — usa pigz de forma transparente."
|
||||
"Registra una desviación de dpkg para el binario <code>gzip</code> del sistema (<code>/usr/bin/gzip</code> en Proxmox VE 9, <code>/bin/gzip</code> en Proxmox VE 8): el binario real se conserva a su lado como <code>gzip.distrib</code> y el wrapper ocupa su lugar. A partir de ahí, <em>cualquier cosa</em> que llame a <code>gzip</code> — logrotate, <code>tar czf</code>, scripts, vzdump — usa pigz de forma transparente.",
|
||||
"Comprueba que el fichero conservado como <code>gzip.distrib</code> es un gzip que funciona antes de colocar el wrapper, y reinstala primero el paquete <code>gzip</code> cuando no lo es. Un host que aún tiene el intercambio anterior con <code>/bin/gzip.original</code> pasa a la desviación al aplicar de nuevo la opción."
|
||||
],
|
||||
"replacesTitle": "Esto sustituye un binario del sistema",
|
||||
"replacesBody": "Sustituir <code>/bin/gzip</code> por un wrapper es inusual. Es seguro (el wrapper produce salida compatible con gzip), pero conviene saberlo: scripts que tengan paths hardcodeados, que se ejecuten dentro de chroots restrictivos o que verifiquen hashes de binarios pueden comportarse de forma distinta. El binario original se conserva como <code>/bin/gzip.original</code> para que siempre puedas dar marcha atrás.",
|
||||
"replacesBody": "Colocar un wrapper en el lugar de <code>gzip</code> es inusual. Es seguro (el wrapper produce salida compatible con gzip), pero conviene saberlo: scripts que tengan paths hardcodeados, que se ejecuten dentro de chroots restrictivos o que verifiquen hashes de binarios pueden comportarse de forma distinta. El binario real se conserva como <code>gzip.distrib</code> y, al ser una desviación de dpkg, una actualización del paquete <code>gzip</code> — o la actualización de Proxmox VE 8 a 9 — actualiza ese fichero y deja el wrapper en su sitio.",
|
||||
"revertTitle": "Reversible desde el menú Uninstall",
|
||||
"revertBody": "Esta optimización está registrada. <link>Uninstall Optimizations</link> restaura <code>/bin/gzip.original</code> en su sitio, elimina el <code>pigzwrapper</code>, revierte las dos líneas añadidas a <code>/etc/vzdump.conf</code> y ejecuta <code>apt purge pigz</code>. Equivalente manual:",
|
||||
"revertBody": "Esta optimización está registrada. <link>Uninstall Optimizations</link> copia el binario real desde <code>gzip.distrib</code> sobre el wrapper, elimina la desviación y el <code>pigzwrapper</code>, comenta la línea <code>pigz</code> de <code>/etc/vzdump.conf</code> y ejecuta <code>apt purge pigz</code> una vez verificado que gzip funciona. Equivalente manual en Proxmox VE 9:",
|
||||
"verifyTitle": "Verificación",
|
||||
"verifyBody": "Tras aplicar, <code>gzip --version</code> debería mencionar pigz. Un benchmark rápido también muestra la diferencia de velocidad en un host multinúcleo:",
|
||||
"whenTitle": "Cuándo importa más",
|
||||
|
||||
@@ -205,7 +205,7 @@
|
||||
},
|
||||
{
|
||||
"tool": "pigz (gzip paralelo)",
|
||||
"restores": "Devuelve /bin/gzip.original a su sitio, elimina /bin/pigzwrapper, revierte las líneas pigz y bwlimit en /etc/vzdump.conf y hace apt purge pigz."
|
||||
"restores": "Copia el gzip real desde gzip.distrib, elimina la desviación de dpkg y /bin/pigzwrapper, comenta la línea pigz en /etc/vzdump.conf y hace apt purge pigz una vez verificado gzip."
|
||||
},
|
||||
{
|
||||
"tool": "High Availability services",
|
||||
|
||||
@@ -78,7 +78,7 @@
|
||||
},
|
||||
{
|
||||
"title": "Actualización del sistema Proxmox",
|
||||
"description": "Higiene de repos + apt update + apt dist-upgrade con preguntar antes de reiniciar. Detecta la versión mayor de PVE (8 o 9) y enruta al worker correspondiente. Cambia a sin suscripción, elimina paquetes conflictivos, ejecuta autoremove.",
|
||||
"description": "Comprobación de repositorios + apt update + apt dist-upgrade con preguntar antes de reiniciar. Detecta la versión mayor de PVE (8 o 9), mantiene los repositorios configurados y pregunta antes de cambiar a sin suscripción un host que no la tiene, y después ejecuta autoremove.",
|
||||
"href": "/docs/utils/system-update"
|
||||
},
|
||||
{
|
||||
|
||||
@@ -7,7 +7,7 @@
|
||||
},
|
||||
"header": {
|
||||
"title": "Actualización del sistema Proxmox",
|
||||
"description": "Wrapper que delega en un único worker seguro (<code>update-pve-safe.sh</code>) que detecta la versión mayor de Proxmox por sí mismo. Los repositorios se limpian cuando se solapan con las fuentes base de Proxmox / Debian, se actualizan todos los paquetes, se recompilan los drivers DKMS gestionados por ProxMenux si aterriza un kernel nuevo y el prompt de reinicio solo se dispara cuando el kernel realmente cambió. También lanzable desde el botón <em>Update Now</em> de la cabecera del dashboard de ProxMenux Monitor cuando se detectan actualizaciones pendientes.",
|
||||
"description": "Wrapper que delega en un único worker seguro (<code>update-pve-safe.sh</code>) que detecta la versión mayor de Proxmox por sí mismo. Los repositorios configurados se leen a través de la API de Proxmox y se mantienen como están; en un host sin suscripción activa cuyo único repositorio de Proxmox es Enterprise se pregunta antes de cambiar a sin suscripción. Se actualizan todos los paquetes, se recompilan los drivers DKMS gestionados por ProxMenux si aterriza un kernel nuevo y el prompt de reinicio solo se dispara cuando el kernel realmente cambió. También lanzable desde el botón <em>Update Now</em> de la cabecera del dashboard de ProxMenux Monitor cuando se detectan actualizaciones pendientes.",
|
||||
"section": "Utilidades"
|
||||
},
|
||||
"calloutWhat": {
|
||||
@@ -25,7 +25,7 @@
|
||||
"intro": "Esta opción ejecuta <strong>exactamente</strong> el comando apt de arriba, envuelto con la higiene de repos, la recompilación DKMS de los drivers gestionados por ProxMenux y la limpieza post-upgrade que la guía oficial de upgrade también recomienda. Todo lo de abajo mapea 1:1 a <code>scripts/utilities/proxmox_update.sh</code> y al único worker seguro <code>scripts/global/update-pve-safe.sh</code> — nada implícito, cada paso está en el código:",
|
||||
"items": [
|
||||
"<strong>Detecta la versión mayor de PVE</strong> desde dentro del worker (<code>pveversion | grep -oP ''pve-manager/\\K[0-9]+''</code>) y adapta las URLs base de repo Proxmox / Debian (bookworm en PVE 8, trixie en PVE 9). No hay reparto a scripts worker por versión — un único worker seguro maneja ambas.",
|
||||
"<strong>Limpia los repositorios de forma conservadora.</strong> <code>ensure_repositories</code> se ejecuta primero pero solo cuando faltan las fuentes base de Proxmox / Debian — un host bare las recibe escritas, un host configurado es un no-op. <code>cleanup_duplicate_repos</code> elimina después duplicados exactos por URL + Suite + Component solo contra <code>proxmox.sources</code> / <code>debian.sources</code>; los archivos propios del usuario (enterprise, Ceph, mirrors NTP alternativos, entradas custom de <code>download.proxmox.com/*</code> o <code>pve-*.list</code> escritos a mano) no se tocan, y cada archivo se respalda antes de editarse.",
|
||||
"<strong>Mantiene los repositorios configurados.</strong> <code>ensure_repositories</code> lee los repositorios a través de la API de repositorios de Proxmox, junto con el estado de la suscripción. Un host con suscripción activa, o que ya usa el repositorio sin suscripción o el de test, se deja sin cambios. En un host sin suscripción activa cuyo único repositorio de Proxmox es Enterprise se pregunta si se cambia a sin suscripción; al rechazarlo, la actualización se detiene sin modificar ninguna fuente.",
|
||||
"<strong>Ejecuta el upgrade no interactivamente</strong> con <code>DEBIAN_FRONTEND=noninteractive</code> y <code>--force-confdef --force-confold</code> — si un archivo de configuración que ya modificaste también cambió upstream, tu versión se queda en su sitio. Sin sobrescrituras silenciosas de configuraciones propias.",
|
||||
"<strong>No fuerza utilidades opcionales.</strong> El worker seguro no empuja <code>zfsutils-linux</code>, <code>chrony</code>, <code>ifupdown2</code> ni paquetes similares al host — una instalación de Proxmox que optó por no tener alguno de ellos conserva su elección. La ausencia de paquetes la surface los flujos de instalación de alto nivel, no la ruta de actualización.",
|
||||
"<strong>Comprobación de sanity de metadatos LVM</strong> contra cabeceras PV sueltas de discos en passthrough (solo aviso, sin arreglo automático).",
|
||||
@@ -63,10 +63,9 @@
|
||||
"heading": "Qué hace el worker",
|
||||
"intro": "Un único worker (<code>scripts/global/update-pve-safe.sh</code>) maneja tanto PVE 8 como PVE 9. Detecta la versión mayor internamente y usa el codename propio de cada versión (<code>bookworm</code> o <code>trixie</code>) para sus fuentes base. Las etapas son:",
|
||||
"items": [
|
||||
"<strong>Comprobaciones previas.</strong> Verifica al menos ~1 GB libres en <code>/var/cache/apt/archives</code> y hace ping a <code>download.proxmox.com</code>. Aborta pronto con un mensaje claro cuando falla cualquiera de las dos, para que la ejecución no muera a mitad de una transacción apt.",
|
||||
"<strong>Bootstrap de repos.</strong> <code>ensure_repositories</code> escribe las fuentes base Proxmox / Debian solo cuando faltan (un host fresco o limpiado a mano); en un host configurado no hace nada.",
|
||||
"<strong>Comprobaciones previas.</strong> Verifica al menos ~1 GB libres en <code>/var/cache/apt/archives</code>. Aborta pronto con un mensaje claro cuando falla, para que la ejecución no muera a mitad de una transacción apt.",
|
||||
"<strong>Comprobación de repositorios.</strong> <code>ensure_repositories</code> lee los repositorios y el estado de la suscripción. En un host con un repositorio de Proxmox utilizable no cambia nada; en un host sin suscripción activa y solo con el repositorio Enterprise pregunta antes de cambiar a sin suscripción, y detiene la actualización cuando la respuesta es no.",
|
||||
"<strong>Apt update con auto-recuperación de GPG.</strong> Ante un <code>NO_PUBKEY</code> de cualquier repo (los propios o uno de terceros), el worker importa la clave que falta y vuelve a intentar automáticamente antes de fallar.",
|
||||
"<strong>Limpieza conservadora de duplicados.</strong> <code>cleanup_duplicate_repos</code> elimina solo coincidencias exactas por URL + Suite + Component contra <code>proxmox.sources</code> / <code>debian.sources</code>. Los archivos propios del usuario — enterprise, Ceph, mirrors NTP alternativos, entradas custom de <code>download.proxmox.com/*</code>, <code>pve-*.list</code> escritos a mano — se dejan intactos. Cada archivo se respalda antes de modificarse.",
|
||||
"<strong>Actualizaciones pendientes + conteo de seguridad.</strong> Reporta cuántos paquetes van a cambiar y cuántos de esos vienen de la suite de seguridad, para que el diálogo de confirmación tenga números reales que mostrar.",
|
||||
"<strong>Diálogo de confirmación.</strong> El wrapper pide un sí explícito antes de tocar apt.",
|
||||
"<strong>apt full-upgrade.</strong> Se ejecuta con <code>DEBIAN_FRONTEND=noninteractive</code> y <code>--force-confdef --force-confold</code> para que cualquier archivo de configuración que personalizaste mantenga su contenido actual cuando upstream también lo cambió. Nunca sobrescribe silenciosamente configs editados por el usuario.",
|
||||
@@ -96,14 +95,16 @@
|
||||
"body": "Correr en un kernel antiguo tras actualizar <code>linux-image-*</code> significa que estás en un sistema medio actualizado: userspace nuevo, kernel viejo. La mayoría del tiempo las cosas funcionan, pero los módulos ZFS, grupos IOMMU, KSMBD y cualquier driver fuera del árbol solo cuadran con el kernel para el que fueron construidos — un desajuste produce fallos oscuros. Reinicia en el primer momento razonable."
|
||||
},
|
||||
"noSub": {
|
||||
"heading": "Cómo trata el worker seguro al repo enterprise",
|
||||
"intro": "Proxmox entrega los hosts con el repo enterprise habilitado por defecto. Sin una suscripción de pago, ese repo devuelve 401 en <code>apt-get update</code>. El worker seguro deliberadamente <strong>no</strong> toca los repositorios enterprise ni Ceph — un host corriendo con una suscripción real no debe verse la configuración reescrita en silencio. Lo que ocurre en su lugar:",
|
||||
"heading": "Cómo trata el worker seguro al repositorio Enterprise",
|
||||
"intro": "Proxmox entrega los hosts con el repositorio Enterprise habilitado por defecto. Sin una suscripción activa, ese repositorio devuelve 401 en <code>apt-get update</code>. El worker seguro cambia los repositorios solo en ese caso, solo tras preguntar, y a través de la API de repositorios de Proxmox — la misma que hay detrás de <em>Nodo → Actualizaciones → Repositorios</em>. Lo que ocurre en cada caso:",
|
||||
"items": [
|
||||
"En un <strong>host bare</strong> sin fuentes base de Proxmox / Debian, <code>ensure_repositories</code> escribe la fuente sin suscripción en formato deb822 (<code>proxmox.sources</code>) con el codename correspondiente a la versión mayor detectada (<code>bookworm</code> para PVE 8, <code>trixie</code> para PVE 9) y las fuentes Debian correspondientes.",
|
||||
"En un <strong>host configurado</strong>, <code>ensure_repositories</code> es un no-op — lo que el usuario haya elegido (sin suscripción, enterprise o una mezcla) se preserva.",
|
||||
"Los archivos enterprise <code>pve-enterprise.sources</code> / <code>ceph.sources</code> nunca son modificados por la ruta de actualización. La eliminación del repo enterprise cuando no se quiere se gestiona desde otra parte de ProxMenux (el script post-instalación automatizado), no desde aquí."
|
||||
"Con una <strong>suscripción activa</strong>, los repositorios se dejan sin cambios y Enterprise dirige la actualización.",
|
||||
"Con el <strong>repositorio sin suscripción o el de test ya habilitado</strong>, los repositorios se dejan sin cambios, sea lo que sea lo que haya configurado a su lado.",
|
||||
"<strong>Sin suscripción activa y solo con el repositorio Enterprise</strong>, un diálogo ofrece el cambio. Al aceptar, se deshabilita la fuente Enterprise, se habilita la de sin suscripción y se refrescan las listas de paquetes; el cambio queda registrado en la vista <em>Changes</em> de Audit & Report. Al rechazarlo, la actualización se detiene sin modificar ninguna fuente.",
|
||||
"Las <strong>fuentes Enterprise de Ceph</strong>, cuando existen, se deshabilitan en el mismo cambio sin elegir otro canal de Ceph; un host que usa Ceph configura su canal por separado.",
|
||||
"Cuando la ejecución <strong>no tiene un terminal en el que preguntar</strong>, no se modifica ninguna fuente y la actualización se detiene con un mensaje que remite a <em>Nodo → Actualizaciones → Repositorios</em>."
|
||||
],
|
||||
"outro": "Si tienes una suscripción de pago, mantén <code>pve-enterprise.sources</code> habilitado y el worker seguro lo dejará dirigir el upgrade sin cambios. Si no la tienes, o bien ejecuta primero el post-instalación automatizado (que hace el cambio y lo registra) o comenta la fuente enterprise a mano — la ruta de actualización no lo hará por ti."
|
||||
"outro": "Las fuentes de Debian y cualquier otro archivo de repositorios nunca se editan desde la ruta de actualización. Una fuente que mezcla Enterprise con otros componentes en la misma entrada no se cambia: la actualización se detiene y pide separarla desde la vista de repositorios de Proxmox."
|
||||
},
|
||||
"cluster": {
|
||||
"heading": "Consideraciones de clúster",
|
||||
@@ -124,7 +125,7 @@
|
||||
"items": [
|
||||
{
|
||||
"title": "apt update falla con 401 Unauthorized",
|
||||
"body": "El repo enterprise sigue habilitado pero no tienes suscripción. El worker debería detectarlo y cambiar automáticamente; si no lo hizo, comenta la línea en <code>/etc/apt/sources.list.d/pve-enterprise.list</code> (o pon <code>Enabled: false</code> en el deb822 <code>pve-enterprise.sources</code>) y vuelve a ejecutar."
|
||||
"body": "El repositorio Enterprise está habilitado y el host no tiene suscripción activa. El worker ofrece el cambio a sin suscripción antes de <code>apt-get update</code>; si se rechazó, ejecuta de nuevo la actualización y acéptalo, o deshabilita la fuente Enterprise en <em>Nodo → Actualizaciones → Repositorios</em> y habilita la de sin suscripción."
|
||||
},
|
||||
{
|
||||
"title": "dist-upgrade se queda colgado en \"Configuring grub-pc\"",
|
||||
@@ -142,7 +143,7 @@
|
||||
},
|
||||
"files": {
|
||||
"heading": "Archivos implicados",
|
||||
"code": "scripts/utilities/proxmox_update.sh # este script (wrapper)\nscripts/global/update-pve-safe.sh # único worker seguro (PVE 8 + PVE 9)\nscripts/global/common-functions.sh # cleanup_duplicate_repos usado por el worker\nscripts/global/utils-install-functions.sh # ensure_repositories + pmx_rebuild_dkms_after_kernel\n/usr/local/share/proxmenux/components_status.json # registro de drivers DKMS gestionados por ProxMenux\n/etc/apt/sources.list.d/proxmox.sources # fuente deb822 sin suscripción (bootstrap host bare)\n/etc/apt/sources.list.d/debian.sources # fuentes deb822 de Debian (bootstrap host bare)\n/var/run/reboot-required # se lee para decidir el prompt de reinicio\n# Fallback de reinicio cuando needrestart no está instalado:\n# dpkg-query -W 'proxmox-kernel-*-pve-signed' 'pve-kernel-*-pve' vs. uname -r"
|
||||
"code": "scripts/utilities/proxmox_update.sh # este script (wrapper)\nscripts/global/update-pve-safe.sh # único worker seguro (PVE 8 + PVE 9)\nscripts/global/repository-functions.sh # ensure_repositories\nscripts/global/repository_policy.py # lee y cambia los repositorios a través de la API de Proxmox\nscripts/global/utils-install-functions.sh # pmx_rebuild_dkms_after_kernel\n/usr/local/share/proxmenux/components_status.json # registro de drivers DKMS gestionados por ProxMenux\n/etc/apt/sources.list.d/proxmox.sources # fuente sin suscripción, escrita por Proxmox al aceptar el cambio\n/var/run/reboot-required # se lee para decidir el prompt de reinicio\n# Fallback de reinicio cuando needrestart no está instalado:\n# dpkg-query -W 'proxmox-kernel-*-pve-signed' 'pve-kernel-*-pve' vs. uname -r"
|
||||
},
|
||||
"related": {
|
||||
"heading": "Relacionado",
|
||||
|
||||
@@ -12,7 +12,7 @@
|
||||
},
|
||||
"info": {
|
||||
"title": "Qué hace",
|
||||
"body": "Instala herramientas CLI de una lista curada de 26 paquetes. Cada instalación pasa por el mismo flujo canónico: <code>ensure_repositories</code> configura los repos Proxmox + Debian para la versión mayor de PVE en ejecución, después <code>install_single_package</code> ejecuta la instalación y verifica que el comando resultante esté en PATH."
|
||||
"body": "Instala herramientas CLI de una lista curada de 26 paquetes. Cada instalación pasa por el mismo flujo canónico: <code>ensure_repositories</code> comprueba que el host tiene un repositorio de Proxmox utilizable para la versión mayor de PVE en ejecución, después <code>install_single_package</code> ejecuta la instalación y verifica que el comando resultante esté en PATH."
|
||||
},
|
||||
"opening": {
|
||||
"heading": "Abrir el instalador",
|
||||
@@ -204,7 +204,7 @@
|
||||
"howItWorks": {
|
||||
"heading": "Cómo funciona la instalación de un paquete",
|
||||
"items": [
|
||||
"<code>ensure_repositories</code> detecta PVE 8 o 9, escribe los archivos de fuentes Proxmox sin suscripción + Debian si faltan, ejecuta <code>apt-get update</code>.",
|
||||
"<code>ensure_repositories</code> detecta PVE 8 o 9 y lee los repositorios a través de la API de Proxmox. Un host con un repositorio de Proxmox utilizable se deja sin cambios; en un host sin suscripción activa y solo con el repositorio Enterprise se pregunta antes de cambiar a sin suscripción, y <code>apt-get update</code> se ejecuta tras un cambio aceptado.",
|
||||
"<code>install_single_package \"pkg\" \"verify_cmd\" \"description\"</code> ejecuta <code>apt-get install -y \"$pkg\"</code> con feedback (<code>msg_info</code> / <code>msg_ok</code> / <code>msg_error</code>)."
|
||||
],
|
||||
"verifyIntro": "Tras instalar, el comando de verificación se comprueba con <code>command -v \"$verify_cmd\"</code>. Tres desenlaces:",
|
||||
@@ -224,7 +224,7 @@
|
||||
"troubleshoot": {
|
||||
"heading": "Solución de problemas",
|
||||
"reposTitle": "\"Failed to configure repositories. Installation aborted.\"",
|
||||
"reposBody": "El host no puede alcanzar los repos de Proxmox o Debian, o no tiene la configuración base esperada. Desde una consola: <code>cat /etc/apt/sources.list /etc/apt/sources.list.d/*.sources</code> y <code>apt-get update</code> manualmente para ver el error real.",
|
||||
"reposBody": "La comprobación de repositorios no se superó: se rechazó el cambio al repositorio sin suscripción, no se pudo leer el estado de la suscripción o una entrada de repositorio requiere atención. El mensaje impreso justo encima indica la causa. Los repositorios se listan en <em>Nodo → Actualizaciones → Repositorios</em>, y <code>apt-get update</code> desde una consola muestra el error que reporta apt.",
|
||||
"warningsTitle": "Un paquete se reporta como \"With warnings\" pero el comando funciona tras cerrar el menú",
|
||||
"warningsBody": "Esperado. Tras <code>apt-get install</code>, el nuevo binario está en disco pero la caché de PATH del shell actual (<code>hash -t</code>) aún no lo sabe. ProxMenux ejecuta <code>hash -r</code> tras cada instalación, pero en algunos shells el refresco solo surte efecto en el siguiente prompt. Abre un nuevo shell y el comando funcionará.",
|
||||
"hangsTitle": "Un apt install se queda colgado",
|
||||
@@ -232,7 +232,7 @@
|
||||
},
|
||||
"files": {
|
||||
"heading": "Archivos implicados",
|
||||
"code": "scripts/utilities/system_utils.sh # this script\nscripts/global/utils-install-functions.sh # PROXMENUX_UTILS, ensure_repositories,\n # install_single_package\n/etc/apt/sources.list # may be touched by ensure_repositories\n/etc/apt/sources.list.d/proxmox.sources # created if missing (PVE 9)\n/etc/apt/sources.list.d/debian.sources # created if missing (PVE 9)\n/etc/apt/sources.list.d/pve-no-subscription.list # created if missing (PVE 8)"
|
||||
"code": "scripts/utilities/system_utils.sh # este script\nscripts/global/utils-install-functions.sh # PROXMENUX_UTILS, install_single_package\nscripts/global/repository-functions.sh # ensure_repositories\nscripts/global/repository_policy.py # lee y cambia los repositorios a través de la API de Proxmox\n/etc/apt/sources.list.d/proxmox.sources # fuente sin suscripción, escrita por Proxmox al aceptar el cambio"
|
||||
},
|
||||
"related": {
|
||||
"heading": "Relacionado",
|
||||
|
||||
Reference in New Issue
Block a user